Bitdefender GravityZone Network Attack Alerts During ConnectSecure Probe Scans

Bitdefender GravityZone Network Attack Alerts During ConnectSecure Probe Scans

This document provides guidance for resolving Network Attack Defense (NAD) alerts generated by Bitdefender GravityZone during scans performed by the ConnectSecure Probe.


Topic - Table of Contents


Watch The Video.png

Visit our YouTube Channel for more video content: https://www.youtube.com/@connectsecure


Overview

Bitdefender GravityZone may generate recurring Network Attack Defense (NAD) alerts when a ConnectSecure Probe performs scheduled network scans.

A commonly reported detection is:

  • Detection: Exploit.PentestingTool.HTTP.3

  • Category: Third-Party AV/EDR Exclusions

  • Affected components: ConnectSecure Probe Agent, Bitdefender GravityZone (Network Attack Defense)

This occurs because Bitdefender’s Network Attack Defense engine can identify legitimate ConnectSecure scanning activity as traffic associated with a penetration-testing tool.


Symptoms

Affected endpoints generate Bitdefender Network Attack Defense alerts during each ConnectSecure scheduled scan.

The alerts may continue even after:

  • Adding ConnectSecure installation paths and executables as standard antivirus exclusions

  • IP Exclusion

  • Confirming that the probe traffic is authorized


Root Cause

Bitdefender’s Network Attack Defense engine analyzes live network traffic patterns rather than files stored on the endpoint.

File-path and executable exclusions configured under Antivirus or Advanced Threat Control (file paths, executables) apply only to those protection modules . They do not prevent detections generated by Network Attack Defense.

The probe's scan traffic also happens to trip a known scanner fingerprint string embedded in the request path, which is why Bitdefender classifies it as a pentesting tool signature rather than legitimate scan traffic.


Resolution

This requires exclusions in two separate places in Bitdefender GravityZone. Both are necessary — neither is sufficient alone.

Step 1: Add antivirus policy exclusions (baseline, not sufficient alone)

Add the following to the Antivirus policy exclusions:

ConnectSecure Installation Path (Windows):

C:\Program Files (x86)\CyberCNSAgent

Executables

connectsecurepatch.exe cybercnsagentmonitor.exe cyberutilities.exe cybercnsagent.exe

This step alone does Not stop NAD alerts. It only covers the Antivirus/ATC modules.

Add the ConnectSecure installation directory and executables to the applicable Bitdefender Antivirus policy.

Step 2: Network Protection exclusions (required for NAD)

  1. Login to the Bitdefender GravityZone Control Center.

  2. Go to Policies.

  3. Open the policy assigned to the affected endpoints.

  4. Expand Network Protection, and then select Exclusions.

  5. Turn on the main Exclusions setting.

  6. In the exclusion grid, select IP/mask from the Type list.

  7. Enter the exact IP address of the ConnectSecure Probe.

  8. Do not include a port number or protocol.

  9. Select Add (+) to move the entry into the active exclusions table.

  10. Save the policy.

Make sure you exclude the IP address of the ConnectSecure Probe, not the IP address of the endpoint receiving the alert.

Step 3: Add Wildcard URL exclusion (confirmed by Bitdefender support — required)

Even after Steps 1–2, scheduled scans may keep generating detections referencing the scanning URL (the source port is ephemeral, so a plain IP exclusion isn't enough).

Add a wildcard URL exclusion under the same Network Protection → Exclusions pane:

HTTP://*/nice%20ports%2C/Tri%6Eity.txt%2ebak

This exclusion addresses the URL pattern associated with the Bitdefender scanner-signature detection.

Step 4: Add the application exclusion (confirmed by Bitdefender support — required)

After Step 3, a separate detection may still appear for a different URL pattern.

Add an application exclusion for:

advanced_ip_scanner.exe

Steps 3 and 4 were recommended by Bitdefender Support for the Network Attack Defense signatures involved in this scenario.

Step 5: Apply the updated policy

To force the policy to synchronize immediately:

  1. Open the Network inventory in Bitdefender GravityZone.

  2. Right-click the affected endpoint or endpoints.

  3. Select Tasks → Reconfigure client.

  4. Allow the task to complete before running another ConnectSecure scan.

Menu names may vary slightly depending on the current GravityZone interface and policy configuration.


Verification

After the updated policy has been applied:

  1. Confirm that the affected endpoints have received the latest Bitdefender policy.

  2. Run or wait for the next scheduled ConnectSecure Probe scan.

  3. Review the Bitdefender Network Attack Defense events.

  4. Confirm that no new Exploit.PentestingTool.HTTP.3 alerts are generated from the authorized probe activity.

This configuration has been verified in a customer environment, with no further alerts reported after the URL and application exclusions were added to the existing antivirus and probe-IP exclusions.


Notes: If the alerts continue

This is a Bitdefender-side configuration issue, not a ConnectSecure defect — no product fix is required.

  • Do not stop at Step 1 (file/process exclusions) when a customer reports NAD-specific alerts (Exploit.PentestingTool.HTTP.3 or similar) — it will not resolve the issue.

  • If a customer reports IP exclusions "not working," check whether they excluded the endpoint IP vs. the probe's IP, and confirm they configured it under Network Protection, not just Antivirus.

  • Steps 3–4 (URL and application exclusions) were identified by Bitdefender's own support team.

  • If steps 1–2 don't fully resolve it, advise the customer to escalate to Bitdefender for the NAD-specific signature exclusion, and reference this article for what to expect.


Need Support?

You can contact our support team by emailing support@connectsecure.com or visiting our Partner Portal, where you can create, view, and manage your tickets.

https://connectsecure.freshdesk.com/en/support/login

image-20240206-144508.png