Cross-source coverage
T1595.002 / ATT&CK
Active Scanning: Vulnerability Scanning
17 rules across 5 sources.
Showing atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application).
- Tactics
- Reconnaissance
- Platforms
- PRE
- Telemetry
-
Network Traffic
How MITRE says to detect it DET0867
Detection of Vulnerability Scanning
PRE Analytic 1999
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Network TrafficNoneNetwork TrafficNone
elastic/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| Web Server Potential SQL Injection Request | High | Elastic TOML |
| Potential Linux Hack Tool Launched | Medium | Elastic TOML |
| Potential Spike in Web Server Error Logs | Low | Elastic TOML |
| Web Server Discovery or Fuzzing Activity | Low | Elastic TOML |
| Web Server Potential Command Injection Request | Low | Elastic TOML |
| Web Server Potential Spike in Error Response Codes | Low | Elastic TOML |
| Web Server Suspicious User Agent Requests | Low | Elastic TOML |
splunk/security_content
5 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Blocked Connection | Undefined | SPL |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Undefined | SPL |
| Cisco Secure Firewall - Repeated Blocked Connections | Undefined | SPL |
| Internal Vulnerability Scan | Undefined | SPL |
| Windows Detect Network Scanner Behavior | Undefined | SPL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| from same source ip. | High | Wazuh XML |
| Multiple web server 501 error code (Not Implemented). | High | Wazuh XML |
panther-labs/panther-analysis
2 rules| Detection | Severity | Format |
|---|---|---|
| Azure Excessive IP and VM Discovery | Medium | Panther Python |
| Azure Excessive Network Security Group Read | Medium | Panther Python |
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| DNS Query to External Service Interaction Domains | High | Sigma |