Wordlist Scanning

T1595.003

Sub-technique of T1595 Active Scanning.View on attack.mitre.org

About this technique

Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal is the identification of content and infrastructure rather than the discovery of valid credentials. Wordlists used in these scans may contain generic, commonly used names and file extensions or terms specific to a particular software. Adversaries may also create custom, target-specific wordlists using data gathered from other Reconnaissance techniques (ex: Gather Victim Org Information, or Search Victim-Owned Websites).

For example, adversaries may use web content discovery tools such as Dirb, DirBuster, and GoBuster and generic or custom wordlists to enumerate a website’s pages and directories. This can help them to discover old, vulnerable pages or hidden administrative portals that could become the target of further operations (ex: Exploit Public-Facing Application or Brute Force).

As cloud storage solutions typically use globally unique names, adversaries may also use target-specific wordlists and tools such as s3recon and GCPBucketBrute to enumerate public and private buckets on cloud infrastructure. Once storage objects are discovered, adversaries may leverage Data from Cloud Storage to access valuable information that can be exfiltrated or used to escalate privileges and move laterally.

Detection rules0

Rules on DetectionCode tagged with T1595.003.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

Groups2

Used byProcedure example
GroupAPT41

APT41 leverages various tools and frameworks to brute-force directories on web servers.

GroupVolatile Cedar

Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.

References3

  1. ClearSky Lebanese Cedar Jan 2021 Open source
    ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.
  2. GCPBucketBrute Open source
    Spencer Gietzen. (2019, February 26). Google Cloud Platform (GCP) Bucket Enumeration and Privilege Escalation. Retrieved March 4, 2022.
  3. S3Recon GitHub Open source
    Travis Clarke. (2020, March 21). S3Recon GitHub. Retrieved March 4, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.