Sub-technique of T1595 Active Scanning.View on attack.mitre.org
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application).
Rules on DetectionCode tagged with T1595.002.
| Rule | Level | Log source |
|---|---|---|
| DNS Query to External Service Interaction Domains | high | NULL / dns |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Secure Firewall - Blocked Connection | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Repeated Blocked Connections | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Internal Vulnerability Scan | TTP | NULL | |
| Windows Detect Network Scanner Behavior | Anomaly | NULL | Sysmon EventID 3 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has performed large-scale scans in an attempt to find vulnerable servers. |
| GroupAPT29 | APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit. |
| GroupAPT41 | APT41 used the Acunetix SQL injection vulnerability scanner in target reconnaissance operations, as well as the JexBoss tool to identify vulnerabilities in Java applications. |
| GroupAquatic Panda | Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228). |
| GroupDragonfly | Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services. |
| GroupEarth Lusca | Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets. |
| GroupEmber Bear | Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure. |
| GroupLeviathan | Leviathan has conducted reconnaissance against target networks of interest looking for vulnerable, end-of-life, or no longer maintainted devices against which to rapidly deploy exploits. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to scan target infrastructure to identify potential vulnerabilities and to enumerate services and endpoints. |
| CampaignCutting Edge | During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors scanned for SharePoint servers vulnerable to CVE-2025-53770. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.