Cross-source coverage

T1018 / ATT&CK

Remote System Discovery

82 rules across 9 sources.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, esxcli network diag ping.

Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.

Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).

Tactics
Discovery
Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:Sysmonauditd:EXECVElinux:syslogmacos:unifiedlogmacos:osqueryesxi:hostdnetworkdevice:syslog

How MITRE says to detect it DET0574

Detection Strategy for Remote System Enumeration Behavior

Windows Analytic 1583

Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1584

Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts.

  • auditd:EXECVE execve
  • linux:syslog network

macOS Analytic 1585

Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents.

  • macos:unifiedlog process
  • macos:osquery file_events

ESXi Analytic 1586

ESXi shell or SSH access issuing `esxcli network diag ping` or viewing routing tables to identify connected hosts.

  • esxi:hostd None

Network Devices Analytic 1587

Execution of discovery commands like `show cdp neighbors`, `show arp`, and other interface-level introspection on Cisco or Juniper devices.

  • networkdevice:syslog syslog facility LOCAL7 or trap messages

socfortress/Wazuh-Rules

22 rules
Detection Severity Format
Remote system discovery attempt via 'ip neighbour show'. High Wazuh XML
Sysmon - Event 1: Process creation · AdFind Computer Enumeration (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · AdFind Domain Controller Enumeration (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · ARP Cache Discovery (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · Get-WmiObject DS_Computers (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · net group Domain Computers (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · Netscan Tool Usage (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · Ping sweep with for loop (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell ADSISearcher Discovery (T1018) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell DirectorySearcher Discovery (T1018) High Wazuh XML

+ 12 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

22 rules
Detection Severity Format
Cisco IOS XE Remote Access Probe Burst Undefined SPL
Cisco Secure Firewall - Blocked Connection Undefined SPL
Cisco Secure Firewall - Repeated Blocked Connections Undefined SPL
Domain Controller Discovery with Nltest Undefined SPL
Domain Controller Discovery with Wmic Undefined SPL
GetAdComputer with PowerShell Undefined SPL
GetAdComputer with PowerShell Script Block Undefined SPL
GetDomainComputer with PowerShell Undefined SPL
GetDomainComputer with PowerShell Script Block Undefined SPL
GetDomainController with PowerShell Undefined SPL

+ 12 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

17 rules
Detection Severity Format
Chopper Webshell Process Pattern High Sigma
HackTool - NetExec Execution High Sigma
PUA - AdFind Suspicious Execution High Sigma
Renamed AdFind Execution High Sigma
Webshell Detection With Command Line Keywords High Sigma
Webshell Hacking Activity Patterns High Sigma
DirectorySearcher Powershell Exploitation Medium Sigma
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock Medium Sigma
Suspicious Scan Loop Network Medium Sigma
Active Directory Computers Enumeration With Get-AdComputer Low Sigma

+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

12 rules
Detection Severity Format
Potential Enumeration via Active Directory Web Service Medium Elastic TOML
Potential Network Scan Executed From Host Medium Elastic TOML
Potential Subnet Scanning Activity from Compromised Host Medium Elastic TOML
Active Directory Discovery using AdExplorer Low Elastic TOML
AdFind Command Activity Low Elastic TOML
DNS Enumeration Detected via Defend for Containers Low Elastic TOML
Enumerating Domain Trusts via DSQUERY.EXE Low Elastic TOML
Enumerating Domain Trusts via NLTEST.EXE Low Elastic TOML
Enumeration Command Spawned via WMIPrvSE Low Elastic TOML
ICMP Timestamp or Information Request from the Internet Low Elastic TOML

+ 2 more from elastic/detection-rules → showing the 10 highest-severity

Emerging Threats Open

3 rules
Detection Severity Format
ET MALWARE APT28 Russia Macro Loader HTTP POST High Suricata
ET WEB_SPECIFIC_APPS Wangshen authManageSet.cgi type Parameter Information Leak Attempt (CVE-2023-7308) High Suricata
ET WEB_SPECIFIC_APPS MedDream PACS Premium cecho.php SSRF Attempt (CVE-2025-24485) Medium Suricata

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Anomalous amount of SMB sessions created (BloodHound) Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
LDAP activity from Powershell process, possible remote system discovery Medium Wazuh XML
Executed Powershell script "Get-ADComputer" executed. Low Wazuh XML

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Probable AdFind Recon Tool Usage (Normalized Process Events) High KQL

panther-labs/panther-analysis

1 rule
Detection Severity Format
Azure Excessive IP and VM Discovery Medium Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.