Technique.View on attack.mitre.org
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.
Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.
Rules on DetectionCode tagged with T1046.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Advanced IP or Port Scanner Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Cisco IOS XE Remote Access Probe Burst | Anomaly | NULL | Cisco IOS Logs |
| Cisco Secure Firewall - Blocked Connection | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Repeated Blocked Connections | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Internal Horizontal Port Scan | TTP | NULL | AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event |
| Internal Horizontal Port Scan NMAP Top 20 | TTP | NULL | AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event |
| Internal Vertical Port Scan | TTP | NULL | AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event |
| Internal Vulnerability Scan | TTP | NULL | |
| Kubernetes Access Scanning | Anomaly | NULL | Kubernetes Audit |
| Kubernetes Scanning by Unauthenticated IP Address | Anomaly | NULL | Kubernetes Audit |
| Windows PsTools Recon Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used the open-source port scanner |
| GroupAPT32 | APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities. |
| GroupAPT39 | APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| GroupAPT41 | APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets. |
| GroupBackdoorDiplomacy | BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware. |
| GroupBlackByte | BlackByte has used tools such as NetScan to enumerate network services in victim environments. |
| GroupBlackTech | BlackTech has used the SNScan tool to find other potential targets on victim networks. |
| GroupChimera | Chimera has used the |
| Used by | Procedure example |
|---|---|
| MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| MalwareBADHATCH | BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| MalwareBlackByte Ransomware | BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
| MalwareBlackEnergy | BlackEnergy has conducted port scans on a host. |
| ToolBrute Ratel C4 | Brute Ratel C4 can conduct port scanning against targeted systems. |
| MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a port scanner on a system. |
| MalwareChina Chopper | China Chopper's server component can spider authentication portals. |
| MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices. |
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms. |
| CampaignC0018 | During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning. |
| CampaignC0027 | During C0027, used RustScan to scan for open ports on targeted ESXi appliances. |
| CampaignCostaRicto | During CostaRicto, the threat actors employed nmap and pscan to scan target environments. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems. |
| CampaignOperation Wocao | During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.