Cross-source coverage
T1018 / ATT&CK
Remote System Discovery
83 rules across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, esxcli network diag ping.
Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.
Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).
- Tactics
- Discovery
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:EXECVElinux:syslogmacos:unifiedlogmacos:osqueryesxi:hostdnetworkdevice:syslog
How MITRE says to detect it DET0574
Detection Strategy for Remote System Enumeration Behavior
Windows Analytic 1583
Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22
Linux Analytic 1584
Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts.
auditd:EXECVEexecvelinux:syslognetwork
macOS Analytic 1585
Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents.
macos:unifiedlogprocessmacos:osqueryfile_events
ESXi Analytic 1586
ESXi shell or SSH access issuing `esxcli network diag ping` or viewing routing tables to identify connected hosts.
esxi:hostdNone
Network Devices Analytic 1587
Execution of discovery commands like `show cdp neighbors`, `show arp`, and other interface-level introspection on Cisco or Juniper devices.
networkdevice:syslogsyslog facility LOCAL7 or trap messages
socfortress/Wazuh-Rules
22 rules| Detection | Severity | Format |
|---|---|---|
| Remote system discovery attempt via 'ip neighbour show'. | High | Wazuh XML |
| Sysmon - Event 1: Process creation · AdFind Computer Enumeration (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · AdFind Domain Controller Enumeration (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · ARP Cache Discovery (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Get-WmiObject DS_Computers (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · net group Domain Computers (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Netscan Tool Usage (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Ping sweep with for loop (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell ADSISearcher Discovery (T1018) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell DirectorySearcher Discovery (T1018) | High | Wazuh XML |
+ 12 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
22 rules| Detection | Severity | Format |
|---|---|---|
| Cisco IOS XE Remote Access Probe Burst | Undefined | SPL |
| Cisco Secure Firewall - Blocked Connection | Undefined | SPL |
| Cisco Secure Firewall - Repeated Blocked Connections | Undefined | SPL |
| Domain Controller Discovery with Nltest | Undefined | SPL |
| Domain Controller Discovery with Wmic | Undefined | SPL |
| GetAdComputer with PowerShell | Undefined | SPL |
| GetAdComputer with PowerShell Script Block | Undefined | SPL |
| GetDomainComputer with PowerShell | Undefined | SPL |
| GetDomainComputer with PowerShell Script Block | Undefined | SPL |
| GetDomainController with PowerShell | Undefined | SPL |
+ 12 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
17 rules| Detection | Severity | Format |
|---|---|---|
| Chopper Webshell Process Pattern | High | Sigma |
| HackTool - NetExec Execution | High | Sigma |
| PUA - AdFind Suspicious Execution | High | Sigma |
| Renamed AdFind Execution | High | Sigma |
| Webshell Detection With Command Line Keywords | High | Sigma |
| Webshell Hacking Activity Patterns | High | Sigma |
| DirectorySearcher Powershell Exploitation | Medium | Sigma |
| Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock | Medium | Sigma |
| Suspicious Scan Loop Network | Medium | Sigma |
| Active Directory Computers Enumeration With Get-AdComputer | Low | Sigma |
+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
12 rules| Detection | Severity | Format |
|---|---|---|
| Potential Enumeration via Active Directory Web Service | Medium | Elastic TOML |
| Potential Network Scan Executed From Host | Medium | Elastic TOML |
| Potential Subnet Scanning Activity from Compromised Host | Medium | Elastic TOML |
| Active Directory Discovery using AdExplorer | Low | Elastic TOML |
| AdFind Command Activity | Low | Elastic TOML |
| DNS Enumeration Detected via Defend for Containers | Low | Elastic TOML |
| Enumerating Domain Trusts via DSQUERY.EXE | Low | Elastic TOML |
| Enumerating Domain Trusts via NLTEST.EXE | Low | Elastic TOML |
| Enumeration Command Spawned via WMIPrvSE | Low | Elastic TOML |
| ICMP Timestamp or Information Request from the Internet | Low | Elastic TOML |
+ 2 more from elastic/detection-rules → showing the 10 highest-severity
Emerging Threats Open
3 rules| Detection | Severity | Format |
|---|---|---|
| ET MALWARE APT28 Russia Macro Loader HTTP POST | High | Suricata |
| ET WEB_SPECIFIC_APPS Wangshen authManageSet.cgi type Parameter Information Leak Attempt (CVE-2023-7308) | High | Suricata |
| ET WEB_SPECIFIC_APPS MedDream PACS Premium cecho.php SSRF Attempt (CVE-2025-24485) | Medium | Suricata |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Anomalous amount of SMB sessions created (BloodHound) | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| LDAP activity from Powershell process, possible remote system discovery | Medium | Wazuh XML |
| Executed Powershell script "Get-ADComputer" executed. | Low | Wazuh XML |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Probable AdFind Recon Tool Usage (Normalized Process Events) | High | KQL |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| remote_system_discovery__ping_sweep | Undefined | YARA-L |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Azure Excessive IP and VM Discovery | Medium | Panther Python |