Search Open Websites/Domains

T1593

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Adversaries may search in different online sites depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: External Remote Services or Phishing).

Detection rules2

Rules on DetectionCode tagged with T1593 or one of its sub-techniques.

Sigma2

RuleLevelLog sourceTechnique
Suspicious Git Clonemediumwindows / process_creationT1593.003
Suspicious Git Clone - Linuxmediumlinux / process_creationT1593.003

Splunk0

No Splunk rules are mapped to this technique yet.

Sub-techniques3

IDNameExamples
T1593.001Social Media4
T1593.002Search Engines2
T1593.003Code Repositories5

Groups6

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

Groups6

Used byProcedure example
GroupAPT-C-36

APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages.

GroupContagious Interview

Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail.

GroupMustang Panda

Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments.

GroupSandworm Team

Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails.

GroupStar Blizzard

Star Blizzard has used open-source research to identify information about victims to use in targeting.

GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise web searches for victim information.

References3

  1. Cyware Social Media Open source
    Cyware Hacker News. (2019, October 2). How Hackers Exploit Social Media To Break Into Your Company. Retrieved October 20, 2020.
  2. ExploitDB GoogleHacking Open source
    Offensive Security. (n.d.). Google Hacking Database. Retrieved October 23, 2020.
  3. SecurityTrails Google Hacking Open source
    Borges, E. (2019, March 5). Exploring Google Hacking Techniques. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.