Cross-source coverage
T1046 / ATT&CK
Network Service Discovery
80 rules · 78 families across 10 sources.
1 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.
Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp.) to find other systems broadcasting the ssh service.
- Tactics
- Discovery
- Platforms
- Containers · IaaS · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlogmacos:osqueryebpf:syscallscontainerd:runtime
How MITRE says to detect it DET0376
Behavioral Detection Strategy for Network Service Discovery Across Platforms
Windows Analytic 1057
Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22
Linux Analytic 1058
Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.
auditd:SYSCALLexecveNSM:FlowOutbound TCP SYN or UDP to multiple ports/hosts
macOS Analytic 1059
Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.
macos:unifiedlogdns-sd, mDNSResponder, socket activitymacos:osqueryprocess_events
Containers Analytic 1060
Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.
ebpf:syscallssocket connectebpf:syscallsexecvecontainerd:runtimecontainer-level outbound traffic events
elastic/detection-rules
20 rules| Detection | Severity | Format |
|---|---|---|
| Hping Process Activity | Medium | Elastic TOML |
| Nping Process Activity | Medium | Elastic TOML |
| Potential Linux Hack Tool Launched | Medium | Elastic TOML |
| Potentially Suspicious Process Started via tmux or screen | Medium | Elastic TOML |
| Potential Network Scan Executed From Host | Medium | Elastic TOML |
| Potential PowerShell HackTool Script by Function Names | Medium | Elastic TOML |
| Potential SIP Extension Enumeration | Medium | Elastic TOML |
| Potential Subnet Scanning Activity from Compromised Host | Medium | Elastic TOML |
| Suricata and Elastic Defend Network Correlation | Medium | Elastic TOML |
| DNS Enumeration Detected via Defend for Containers | Low | Elastic TOML |
+ 10 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
19 rules| Detection | Severity | Format |
|---|---|---|
| Grixba Malware Reconnaissance Activity | High | Sigma |
| HackTool - winPEAS Execution | High | Sigma |
| HackTool - WinPwn Execution | High | Sigma |
| HackTool - WinPwn Execution - ScriptBlock | High | Sigma |
| OpenCanary - Host Port Scan (SYN Scan) | High | Sigma |
| OpenCanary - NMAP FIN Scan | High | Sigma |
| OpenCanary - NMAP NULL Scan | High | Sigma |
| OpenCanary - NMAP OS Scan | High | Sigma |
| OpenCanary - NMAP XMAS Scan | High | Sigma |
| Advanced IP Scanner - File Event | Medium | Sigma |
+ 9 more from SigmaHQ/sigma → showing the 10 highest-severity
socfortress/Wazuh-Rules
14 rules · 13 families| Detection | Severity | Format |
|---|---|---|
| Detects enumeration of local or remote network services. 2 variants | High | Wazuh XML |
| Detects enumeration of local or remote network services. 2 variants | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Netcat Port Scan (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell RDP Services Check (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Subnet Port Scan (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Python Port Scanner (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Telnet Port Scan (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · WinPwn BlueKeep Scan (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · WinPwn MS17-10 Scan (T1046) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · WinPwn Spool Vulnerability Scan (T1046) | High | Wazuh XML |
+ 4 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
11 rules| Detection | Severity | Format |
|---|---|---|
| Advanced IP or Port Scanner Execution | Undefined | SPL |
| Cisco IOS XE Remote Access Probe Burst | Undefined | SPL |
| Cisco Secure Firewall - Blocked Connection | Undefined | SPL |
| Cisco Secure Firewall - Repeated Blocked Connections | Undefined | SPL |
| Internal Horizontal Port Scan | Undefined | SPL |
| Internal Horizontal Port Scan NMAP Top 20 | Undefined | SPL |
| Internal Vertical Port Scan | Undefined | SPL |
| Internal Vulnerability Scan | Undefined | SPL |
| Kubernetes Access Scanning | Undefined | SPL |
| Kubernetes Scanning by Unauthenticated IP Address | Undefined | SPL |
+ 1 more from splunk/security_content → showing the 10 highest-severity
panther-labs/panther-analysis
5 rules| Detection | Severity | Format |
|---|---|---|
| Azure Excessive IP and VM Discovery | Medium | Panther Python |
| Azure Excessive Network Security Group Read | Medium | Panther Python |
| Teleport Network Scan Initiated | Medium | Panther Python |
| Upwind Network Detection Passthrough | Medium | Panther Python |
| VPC Flow Port Scanning | Medium | Panther Python |
Emerging Threats Open
4 rules · 3 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE IP Check With Minimal Headers and Custom User-Agent (Common Host Profiling Technique) | High | Suricata |
| ET WEB_SPECIFIC_APPS [aretiq.ai] Exchange EWS InstallApp with ManifestUrl Server-Side Request Forgery Attempt (CVE-2026-45502) | High | Suricata |
| ET INFO Insecure Proxy Discovery via AWS Instance Metadata Retrieval M1 2 variants | Informational | Suricata |
| ET INFO Insecure Proxy Discovery via AWS Instance Metadata Retrieval M2 2 variants | Informational | Suricata |
Wazuh Core Ruleset
3 rules| Detection | Severity | Format |
|---|---|---|
| Connection to rshd from unprivileged port. Possible network scan. | High | Wazuh XML |
| Network scan from same source ip. | High | Wazuh XML |
| sshd: SSH Scanning. | Medium | Wazuh XML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Database Disovery | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| A host is potentially running a hacking tool (ASIM Web Session schema) | Medium | KQL |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Network Connection outside Local Subnet | Medium | Falco YAML |