Cross-source coverage

T1593 / ATT&CK

Search Open Websites/Domains

5 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Adversaries may search in different online sites depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: External Remote Services or Phishing).

Tactics
Reconnaissance
Platforms
PRE
Telemetry

How MITRE says to detect it DET0856

Detection of Search Open Websites/Domains

PRE Analytic 1988

Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Sub-techniques with coverage

Counted in the 5 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

3 rules
Detection Severity Format
ET MALWARE Yandexbot Request Outbound Medium Suricata
ET POLICY Majestic12 User-Agent Request Outbound Informational Suricata
ET SCAN Yahoo Crawler Crawl Informational Suricata

SigmaHQ/sigma

2 rules
Detection Severity Format
Suspicious Git Clone Medium Sigma
Suspicious Git Clone - Linux Medium Sigma

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.