Network Service Discovery

T1046

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.

Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.

Detection rules30

Rules on DetectionCode tagged with T1046.

Sigma19

RuleLevelLog source
HackTool - winPEAS Executionhighwindows / process_creation
HackTool - WinPwn Executionhighwindows / process_creation
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_script
OpenCanary - Host Port Scan (SYN Scan)highopencanary / application
OpenCanary - NMAP FIN Scanhighopencanary / application
OpenCanary - NMAP NULL Scanhighopencanary / application
OpenCanary - NMAP OS Scanhighopencanary / application
OpenCanary - NMAP XMAS Scanhighopencanary / application
Advanced IP Scanner - File Eventmediumwindows / file_event
Pnscan Binary Data Transmission Activitymediumlinux / process_creation
PUA - Advanced IP Scanner Executionmediumwindows / process_creation
PUA - Advanced Port Scanner Executionmediumwindows / process_creation
PUA - NimScan Executionmediumwindows / process_creation
PUA - Nmap/Zenmap Executionmediumwindows / process_creation
PUA - SoftPerfect Netscan Executionmediumwindows / process_creation

Splunk11

RuleTypeRiskData source
Advanced IP or Port Scanner ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Cisco IOS XE Remote Access Probe BurstAnomalyNULLCisco IOS Logs
Cisco Secure Firewall - Blocked ConnectionAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Repeated Blocked ConnectionsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Internal Horizontal Port ScanTTPNULLAWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
Internal Horizontal Port Scan NMAP Top 20TTPNULLAWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
Internal Vertical Port ScanTTPNULLAWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
Internal Vulnerability ScanTTPNULL
Kubernetes Access ScanningAnomalyNULLKubernetes Audit
Kubernetes Scanning by Unauthenticated IP AddressAnomalyNULLKubernetes Audit
Windows PsTools Recon UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups31

Show 7 more

Software35

Show 11 more

Campaigns7

Procedure examples73

Groups31

Used byProcedure example
GroupAgrius

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.

GroupAPT32

APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities.

GroupAPT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

GroupAPT41

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.

GroupBackdoorDiplomacy

BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware.

GroupBlackByte

BlackByte has used tools such as NetScan to enumerate network services in victim environments.

GroupBlackTech

BlackTech has used the SNScan tool to find other potential targets on victim networks.

GroupChimera

Chimera has used the get -b <start ip> -e <end ip> -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.

View all 31 groups examples

Software35

Used byProcedure example
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.

MalwareBADHATCH

BADHATCH can check for open ports on a computer by establishing a TCP connection.

MalwareBlackByte Ransomware

BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads.

MalwareBlackEnergy

BlackEnergy has conducted port scans on a host.

ToolBrute Ratel C4

Brute Ratel C4 can conduct port scanning against targeted systems.

MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a port scanner on a system.

MalwareChina Chopper

China Chopper's server component can spider authentication portals.

MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

View all 35 software examples

Campaigns7

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms.

CampaignC0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.

CampaignC0027

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.

CampaignCostaRicto

During CostaRicto, the threat actors employed nmap and pscan to scan target environments.

CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

CampaignOperation Wocao

During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers.

References3

  1. CISA AR21-126A FIVEHANDS May 2021 Open source
    CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.
  2. apple doco bonjour description Open source
    Apple Inc. (2013, April 23). Bonjour Overview. Retrieved October 11, 2021.
  3. macOS APT Activity Bradley Open source
    Jaron Bradley. (2021, November 14). What does APT Activity Look Like on macOS?. Retrieved January 19, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.