Cross-source coverage

T1595.002 / ATT&CK

Active Scanning: Vulnerability Scanning

16 rules across 4 sources.

1 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application).

Tactics
Reconnaissance
Platforms
PRE
Telemetry
Network Traffic

How MITRE says to detect it DET0867

Detection of Vulnerability Scanning

PRE Analytic 1999

Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

  • Network Traffic None
  • Network Traffic None

elastic/detection-rules

7 rules
Detection Severity Format
Web Server Potential SQL Injection Request High Elastic TOML
Potential Linux Hack Tool Launched Medium Elastic TOML
Potential Spike in Web Server Error Logs Low Elastic TOML
Web Server Discovery or Fuzzing Activity Low Elastic TOML
Web Server Potential Command Injection Request Low Elastic TOML
Web Server Potential Spike in Error Response Codes Low Elastic TOML
Web Server Suspicious User Agent Requests Low Elastic TOML

splunk/security_content

5 rules
Detection Severity Format
Cisco Secure Firewall - Blocked Connection Undefined SPL
Cisco Secure Firewall - High Volume of Intrusion Events Per Host Undefined SPL
Cisco Secure Firewall - Repeated Blocked Connections Undefined SPL
Internal Vulnerability Scan Undefined SPL
Windows Detect Network Scanner Behavior Undefined SPL

Wazuh Core Ruleset

2 rules
Detection Severity Format
from same source ip. High Wazuh XML
Multiple web server 501 error code (Not Implemented). High Wazuh XML

panther-labs/panther-analysis

2 rules
Detection Severity Format
Azure Excessive IP and VM Discovery Medium Panther Python
Azure Excessive Network Security Group Read Medium Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.