Don’t worry, it is safe. From this Microsoft document we can see:
My security tool raised alert on UnicastScanner.ps1 or port scanning activity initiated by it, what should I do?
The active probing scripts are signed by Microsoft and are safe. You can add the following path to your exclusion list: C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Downloads*.ps
https://github.com/MicrosoftDocs/microsoft-365-docs/blob/public/microsoft-365/security/defender-endpoint/device-discovery-faq.md
More information here:
Device discovery overview
Standard discovery uses various PowerShell scripts to actively probe devices in the network. Those PowerShell scripts are Microsoft signed and are executed from the following location: C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Downloads*.ps
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-discovery?view=o365-worldwide
-------------------------------------------------------------------------------------
If the Answer is helpful, please click "Accept Answer" and upvote it.
Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.