Active Scanning

T1595

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Exploit Public-Facing Application).

Detection rules17

Rules on DetectionCode tagged with T1595 or one of its sub-techniques.

Sigma4

Splunk13

RuleTypeRiskData sourceTechnique
Attacker Tools On EndpointTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow DataT1595
Cisco SA - Automated Web Reconnaissance via HTTP Access ErrorsAnomalyNULLCisco Secure Access ProxyT1595
Cisco SD-WAN - Uncommon User-Agent Multi-URI ActivityHuntingNULLCisco SD-WAN Service Proxy Access LogsT1595
Cisco SD-WAN Multiple Source IP vManage Admin SSH AuthenticationHuntingNULLCisco SD-WAN Auth LogT1595
Cisco SD-WAN Multiple SSH key Authentication from Same SourceHuntingNULLCisco SD-WAN Auth LogT1595
Cisco Secure Firewall - Blocked ConnectionAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1595.002
Cisco Secure Firewall - High Volume of Intrusion Events Per HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1595.002
Cisco Secure Firewall - Repeated Blocked ConnectionsAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1595.002
HTTP Rapid POST with Mixed Status CodesAnomalyNULLNginx AccessT1595
Internal Vulnerability ScanTTPNULLT1595.002
Ollama Possible API Endpoint Scan ReconnaissanceAnomalyNULLOllama ServerT1595
Windows Detect Network Scanner BehaviorAnomalyNULLSysmon EventID 3T1595.001 T1595.002
Windows Netspy Network Scanner ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1595

Sub-techniques3

IDNameExamples
T1595.001Scanning IP Blocks3
T1595.002Vulnerability Scanning18
T1595.003Wordlist Scanning2

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples1

Campaigns1

Used byProcedure example
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest.

References2

  1. Botnet Scan Open source
    Dainotti, A. et al. (2012). Analysis of a “/0” Stealth Scan from a Botnet. Retrieved October 20, 2020.
  2. OWASP Fingerprinting Open source
    OWASP Wiki. (2018, February 16). OAT-004 Fingerprinting. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.