Cross-source coverage

T1595.001 / ATT&CK

Active Scanning: Scanning IP Blocks

11 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.

Adversaries may scan IP blocks in order to Gather Victim Network Information, such as which IP addresses are actively in use as well as more detailed information about hosts assigned these addresses. Scans may range from simple pings (ICMP requests and responses) to more nuanced scans that may reveal host software/versions via server banners or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services).

Tactics
Reconnaissance
Platforms
PRE
Telemetry
Network Traffic

How MITRE says to detect it DET0817

Detection of Scanning IP Blocks

PRE Analytic 1949

Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network. Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

  • Network Traffic None
  • Network Traffic None

elastic/detection-rules

6 rules
Detection Severity Format
ICMP Timestamp or Information Request from the Internet Low Elastic TOML
Potential Network Scan Detected Low Elastic TOML
Potential Network Sweep Detected Low Elastic TOML
Potential SYN-Based Port Scan Detected Low Elastic TOML
Spike in Network Traffic To a Country Low Elastic TOML
Web Server Suspicious User Agent Requests Low Elastic TOML

panther-labs/panther-analysis

3 rules
Detection Severity Format
GreyNoise V3 Malicious IP Activity High Panther Python
GTI/VirusTotal Threat Intelligence Indicator Match High Panther Python
OTX Threat Intelligence Indicator Match High Panther Python

SigmaHQ/sigma

1 rule
Detection Severity Format
Grixba Malware Reconnaissance Activity High Sigma

splunk/security_content

1 rule
Detection Severity Format
Windows Detect Network Scanner Behavior Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.