Cross-source coverage
T1593 / ATT&CK
Search Open Websites/Domains
4 rules across 2 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.
Adversaries may search in different online sites depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: External Remote Services or Phishing).
- Tactics
- Reconnaissance
- Platforms
- PRE
- Telemetry
- —
How MITRE says to detect it DET0856
Detection of Search Open Websites/Domains
PRE Analytic 1988
Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
Sub-techniques with coverage
Counted in the 4 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
2 rules| Detection | Severity | Format |
|---|---|---|
| ET MALWARE Yandexbot Request Outbound | Medium | Suricata |
| ET POLICY Majestic12 User-Agent Request Outbound | Informational | Suricata |
SigmaHQ/sigma
2 rules| Detection | Severity | Format |
|---|---|---|
| Suspicious Git Clone | Medium | Sigma |
| Suspicious Git Clone - Linux | Medium | Sigma |