Bitdefender GravityZone Network Attack Alerts During ConnectSecure Probe Scans
This document provides guidance for resolving Network Attack Defense (NAD) alerts generated by Bitdefender GravityZone during scans performed by the ConnectSecure Probe.
Topic - Table of Contents
- 1 Overview
- 2 Symptoms
- 3 Root Cause
- 4 Resolution
- 4.1 Step 1: Add antivirus policy exclusions (baseline, not sufficient alone)
- 4.2 Step 2: Network Protection exclusions (required for NAD)
- 4.3 Step 3: Add Wildcard URL exclusion (confirmed by Bitdefender support — required)
- 4.4 Step 4: Add the application exclusion (confirmed by Bitdefender support — required)
- 4.5 Step 5: Apply the updated policy
- 5 Verification
- 6 Notes: If the alerts continue
- 7 Need Support?
Visit our YouTube Channel for more video content: https://www.youtube.com/@connectsecure
Overview
Bitdefender GravityZone may generate recurring Network Attack Defense (NAD) alerts when a ConnectSecure Probe performs scheduled network scans.
A commonly reported detection is:
Detection:
Exploit.PentestingTool.HTTP.3Category: Third-Party AV/EDR Exclusions
Affected components: ConnectSecure Probe Agent, Bitdefender GravityZone (Network Attack Defense)
This occurs because Bitdefender’s Network Attack Defense engine can identify legitimate ConnectSecure scanning activity as traffic associated with a penetration-testing tool.
Symptoms
Affected endpoints generate Bitdefender Network Attack Defense alerts during each ConnectSecure scheduled scan.
The alerts may continue even after:
Adding ConnectSecure installation paths and executables as standard antivirus exclusions
IP Exclusion
Confirming that the probe traffic is authorized
Root Cause
Bitdefender’s Network Attack Defense engine analyzes live network traffic patterns rather than files stored on the endpoint.
File-path and executable exclusions configured under Antivirus or Advanced Threat Control (file paths, executables) apply only to those protection modules . They do not prevent detections generated by Network Attack Defense.
The probe's scan traffic also happens to trip a known scanner fingerprint string embedded in the request path, which is why Bitdefender classifies it as a pentesting tool signature rather than legitimate scan traffic.
Resolution
This requires exclusions in two separate places in Bitdefender GravityZone. Both are necessary — neither is sufficient alone.
Step 1: Add antivirus policy exclusions (baseline, not sufficient alone)
Add the following to the Antivirus policy exclusions:
ConnectSecure Installation Path (Windows):
C:\Program Files (x86)\CyberCNSAgentExecutables
connectsecurepatch.exe
cybercnsagentmonitor.exe
cyberutilities.exe
cybercnsagent.exeThis step alone does Not stop NAD alerts. It only covers the Antivirus/ATC modules.
Add the ConnectSecure installation directory and executables to the applicable Bitdefender Antivirus policy.
Step 2: Network Protection exclusions (required for NAD)
Login to the Bitdefender GravityZone Control Center.
Go to Policies.
Open the policy assigned to the affected endpoints.
Expand Network Protection, and then select Exclusions.
Turn on the main Exclusions setting.
In the exclusion grid, select IP/mask from the Type list.
Enter the exact IP address of the ConnectSecure Probe.
Do not include a port number or protocol.
Select Add (+) to move the entry into the active exclusions table.
Save the policy.
Make sure you exclude the IP address of the ConnectSecure Probe, not the IP address of the endpoint receiving the alert.
Step 3: Add Wildcard URL exclusion (confirmed by Bitdefender support — required)
Even after Steps 1–2, scheduled scans may keep generating detections referencing the scanning URL (the source port is ephemeral, so a plain IP exclusion isn't enough).
Add a wildcard URL exclusion under the same Network Protection → Exclusions pane:
HTTP://*/nice%20ports%2C/Tri%6Eity.txt%2ebakThis exclusion addresses the URL pattern associated with the Bitdefender scanner-signature detection.
Step 4: Add the application exclusion (confirmed by Bitdefender support — required)
After Step 3, a separate detection may still appear for a different URL pattern.
Add an application exclusion for:
advanced_ip_scanner.exeSteps 3 and 4 were recommended by Bitdefender Support for the Network Attack Defense signatures involved in this scenario.
Step 5: Apply the updated policy
To force the policy to synchronize immediately:
Open the Network inventory in Bitdefender GravityZone.
Right-click the affected endpoint or endpoints.
Select Tasks → Reconfigure client.
Allow the task to complete before running another ConnectSecure scan.
Menu names may vary slightly depending on the current GravityZone interface and policy configuration.
Verification
After the updated policy has been applied:
Confirm that the affected endpoints have received the latest Bitdefender policy.
Run or wait for the next scheduled ConnectSecure Probe scan.
Review the Bitdefender Network Attack Defense events.
Confirm that no new
Exploit.PentestingTool.HTTP.3alerts are generated from the authorized probe activity.
This configuration has been verified in a customer environment, with no further alerts reported after the URL and application exclusions were added to the existing antivirus and probe-IP exclusions.
Notes: If the alerts continue
This is a Bitdefender-side configuration issue, not a ConnectSecure defect — no product fix is required.
Do not stop at Step 1 (file/process exclusions) when a customer reports NAD-specific alerts (
Exploit.PentestingTool.HTTP.3or similar) — it will not resolve the issue.If a customer reports IP exclusions "not working," check whether they excluded the endpoint IP vs. the probe's IP, and confirm they configured it under Network Protection, not just Antivirus.
Steps 3–4 (URL and application exclusions) were identified by Bitdefender's own support team.
If steps 1–2 don't fully resolve it, advise the customer to escalate to Bitdefender for the NAD-specific signature exclusion, and reference this article for what to expect.
Need Support?
You can contact our support team by emailing support@connectsecure.com or visiting our Partner Portal, where you can create, view, and manage your tickets.
https://connectsecure.freshdesk.com/en/support/login