Cross-source coverage

T1595 / ATT&CK

Active Scanning

52 rules across 7 sources.

1 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Exploit Public-Facing Application).

Tactics
Reconnaissance
Platforms
PRE
Telemetry
Network Traffic

How MITRE says to detect it DET0830

Detection of Active Scanning

PRE Analytic 1962

Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

  • Network Traffic None
  • Network Traffic None

Sub-techniques with coverage

Counted in the 52 above — a rule tagged a sub-technique covers this technique too.


elastic/detection-rules

20 rules
Detection Severity Format
Web Server Potential SQL Injection Request High Elastic TOML
GKE Anonymous Endpoint Permission Enumeration Medium Elastic TOML
Inbound Connection to an Unsecure Elasticsearch Node Medium Elastic TOML
Kubernetes Potential Endpoint Permission Enumeration Attempt by Anonymous User Detected Medium Elastic TOML
Potential Linux Hack Tool Launched Medium Elastic TOML
Potential SIP Extension Enumeration Medium Elastic TOML
ICMP Timestamp or Information Request from the Internet Low Elastic TOML
Potential Network Scan Detected Low Elastic TOML
Potential Network Sweep Detected Low Elastic TOML
Potential Spike in Web Server Error Logs Low Elastic TOML

+ 10 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

13 rules
Detection Severity Format
Attacker Tools On Endpoint Undefined SPL
Cisco SA - Automated Web Reconnaissance via HTTP Access Errors Undefined SPL
Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication Undefined SPL
Cisco SD-WAN Multiple SSH key Authentication from Same Source Undefined SPL
Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity Undefined SPL
Cisco Secure Firewall - Blocked Connection Undefined SPL
Cisco Secure Firewall - High Volume of Intrusion Events Per Host Undefined SPL
Cisco Secure Firewall - Repeated Blocked Connections Undefined SPL
HTTP Rapid POST with Mixed Status Codes Undefined SPL
Internal Vulnerability Scan Undefined SPL

+ 3 more from splunk/security_content → showing the 10 highest-severity

panther-labs/panther-analysis

8 rules
Detection Severity Format
GSuite Government Backed Attack Critical Panther Python
GreyNoise V3 Malicious IP Activity High Panther Python
GTI/VirusTotal Threat Intelligence Indicator Match High Panther Python
OTX Threat Intelligence Indicator Match High Panther Python
Azure Excessive IP and VM Discovery Medium Panther Python
Azure Excessive Network Security Group Read Medium Panther Python
AWS WAF Managed Bot Control Passthrough Rule Informational Panther Python
AWS WAF Managed IP Reputation Passthrough Rule Informational Panther Python

SigmaHQ/sigma

4 rules
Detection Severity Format
Grixba Malware Reconnaissance Activity High Sigma
PUA - PingCastle Execution From Potentially Suspicious Parent High Sigma
Potential Hello-World Scraper Botnet Activity Medium Sigma
PUA - PingCastle Execution Medium Sigma

Wazuh Core Ruleset

3 rules
Detection Severity Format
from same source ip. High Wazuh XML
MS-DHCP: Packet dropped due to NAP policy. High Wazuh XML
Multiple web server 501 error code (Not Implemented). High Wazuh XML

socfortress/Wazuh-Rules

3 rules
Detection Severity Format
Sysmon - Event 1: Process creation · Wordlist Scanning with PowerShell (T1595.003) High Wazuh XML
Possible wordlist scanning based on known filename patterns (T1595.003) Medium Wazuh XML
Wordlist scanning tool execution detected (T1595.003) Medium Wazuh XML

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Detect Enumeration Activity Using Unique Identifiers and Session Aggregation Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.