Cross-source coverage

T1046 / ATT&CK

Network Service Discovery

81 rules · 79 families across 10 sources.

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.

Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp.) to find other systems broadcasting the ssh service.

Tactics
Discovery
Platforms
Containers · IaaS · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLNSM:Flowmacos:unifiedlogmacos:osqueryebpf:syscallscontainerd:runtime

How MITRE says to detect it DET0376

Behavioral Detection Strategy for Network Service Discovery Across Platforms

Windows Analytic 1057

Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1058

Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.

  • auditd:SYSCALL execve
  • NSM:Flow Outbound TCP SYN or UDP to multiple ports/hosts

macOS Analytic 1059

Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.

  • macos:unifiedlog dns-sd, mDNSResponder, socket activity
  • macos:osquery process_events

Containers Analytic 1060

Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.

  • ebpf:syscalls socket connect
  • ebpf:syscalls execve
  • containerd:runtime container-level outbound traffic events

SigmaHQ/sigma

20 rules
Detection Severity Format
Grixba Malware Reconnaissance Activity High Sigma
HackTool - winPEAS Execution High Sigma
HackTool - WinPwn Execution High Sigma
HackTool - WinPwn Execution - ScriptBlock High Sigma
OpenCanary - Host Port Scan (SYN Scan) High Sigma
OpenCanary - NMAP FIN Scan High Sigma
OpenCanary - NMAP NULL Scan High Sigma
OpenCanary - NMAP OS Scan High Sigma
OpenCanary - NMAP XMAS Scan High Sigma
Advanced IP Scanner - File Event Medium Sigma

+ 10 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

20 rules
Detection Severity Format
Hping Process Activity Medium Elastic TOML
Nping Process Activity Medium Elastic TOML
Potential Linux Hack Tool Launched Medium Elastic TOML
Potentially Suspicious Process Started via tmux or screen Medium Elastic TOML
Potential Network Scan Executed From Host Medium Elastic TOML
Potential PowerShell HackTool Script by Function Names Medium Elastic TOML
Potential SIP Extension Enumeration Medium Elastic TOML
Potential Subnet Scanning Activity from Compromised Host Medium Elastic TOML
Suricata and Elastic Defend Network Correlation Medium Elastic TOML
DNS Enumeration Detected via Defend for Containers Low Elastic TOML

+ 10 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

14 rules · 13 families
Detection Severity Format
Detects enumeration of local or remote network services. 2 variants High Wazuh XML
Detects enumeration of local or remote network services. 2 variants High Wazuh XML
Sysmon - Event 1: Process creation · Netcat Port Scan (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell RDP Services Check (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Subnet Port Scan (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · Python Port Scanner (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · Telnet Port Scan (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · WinPwn BlueKeep Scan (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · WinPwn MS17-10 Scan (T1046) High Wazuh XML
Sysmon - Event 1: Process creation · WinPwn Spool Vulnerability Scan (T1046) High Wazuh XML

+ 4 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

11 rules
Detection Severity Format
Advanced IP or Port Scanner Execution Undefined SPL
Cisco IOS XE Remote Access Probe Burst Undefined SPL
Cisco Secure Firewall - Blocked Connection Undefined SPL
Cisco Secure Firewall - Repeated Blocked Connections Undefined SPL
Internal Horizontal Port Scan Undefined SPL
Internal Horizontal Port Scan NMAP Top 20 Undefined SPL
Internal Vertical Port Scan Undefined SPL
Internal Vulnerability Scan Undefined SPL
Kubernetes Access Scanning Undefined SPL
Kubernetes Scanning by Unauthenticated IP Address Undefined SPL

+ 1 more from splunk/security_content → showing the 10 highest-severity

panther-labs/panther-analysis

5 rules
Detection Severity Format
Azure Excessive IP and VM Discovery Medium Panther Python
Azure Excessive Network Security Group Read Medium Panther Python
Teleport Network Scan Initiated Medium Panther Python
Upwind Network Detection Passthrough Medium Panther Python
VPC Flow Port Scanning Medium Panther Python

Emerging Threats Open

4 rules · 3 families
Detection Severity Format
ET MALWARE IP Check With Minimal Headers and Custom User-Agent (Common Host Profiling Technique) High Suricata
ET WEB_SPECIFIC_APPS [aretiq.ai] Exchange EWS InstallApp with ManifestUrl Server-Side Request Forgery Attempt (CVE-2026-45502) High Suricata
ET INFO Insecure Proxy Discovery via AWS Instance Metadata Retrieval M1 2 variants Informational Suricata
ET INFO Insecure Proxy Discovery via AWS Instance Metadata Retrieval M2 2 variants Informational Suricata

Wazuh Core Ruleset

3 rules
Detection Severity Format
Connection to rshd from unprivileged port. Possible network scan. High Wazuh XML
Network scan from same source ip. High Wazuh XML
sshd: SSH Scanning. Medium Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Database Disovery Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Azure/Azure-Sentinel

1 rule
Detection Severity Format
A host is potentially running a hacking tool (ASIM Web Session schema) Medium KQL

falcosecurity/rules

1 rule
Detection Severity Format
Network Connection outside Local Subnet Medium Falco YAML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.