PUA - Nmap/Zenmap Execution — Detection Rule

Detects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation

Read the full analysis on IntelFusions