Vulnerability Scanning

T1595.002

Sub-technique of T1595 Active Scanning.View on attack.mitre.org

About this technique

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application).

Detection rules6

Rules on DetectionCode tagged with T1595.002.

Sigma1

RuleLevelLog source
DNS Query to External Service Interaction DomainshighNULL / dns

Splunk5

RuleTypeRiskData source
Cisco Secure Firewall - Blocked ConnectionAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - High Volume of Intrusion Events Per HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Repeated Blocked ConnectionsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Internal Vulnerability ScanTTPNULL
Windows Detect Network Scanner BehaviorAnomalyNULLSysmon EventID 3

Groups15

Software0

None recorded.

Campaigns3

Procedure examples18

Groups15

Used byProcedure example
GroupAPT28

APT28 has performed large-scale scans in an attempt to find vulnerable servers.

GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

GroupAPT41

APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications.

GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

GroupDragonfly

Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services.

GroupEarth Lusca

Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets.

GroupEmber Bear

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.

GroupLeviathan

Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits.

View all 15 groups examples

Campaigns3

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints.

CampaignCutting Edge

During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770.

References1

  1. OWASP Vuln Scanning Open source
    OWASP. (n.d.). OAT-014 Vulnerability Scanning. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.