Cross-source coverage
T1595 / ATT&CK
Active Scanning
52 rules across 7 sources.
1 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.
Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Exploit Public-Facing Application).
- Tactics
- Reconnaissance
- Platforms
- PRE
- Telemetry
-
Network Traffic
How MITRE says to detect it DET0830
Detection of Active Scanning
PRE Analytic 1962
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Network TrafficNoneNetwork TrafficNone
Sub-techniques with coverage
Counted in the 52 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
20 rules| Detection | Severity | Format |
|---|---|---|
| Web Server Potential SQL Injection Request | High | Elastic TOML |
| GKE Anonymous Endpoint Permission Enumeration | Medium | Elastic TOML |
| Inbound Connection to an Unsecure Elasticsearch Node | Medium | Elastic TOML |
| Kubernetes Potential Endpoint Permission Enumeration Attempt by Anonymous User Detected | Medium | Elastic TOML |
| Potential Linux Hack Tool Launched | Medium | Elastic TOML |
| Potential SIP Extension Enumeration | Medium | Elastic TOML |
| ICMP Timestamp or Information Request from the Internet | Low | Elastic TOML |
| Potential Network Scan Detected | Low | Elastic TOML |
| Potential Network Sweep Detected | Low | Elastic TOML |
| Potential Spike in Web Server Error Logs | Low | Elastic TOML |
+ 10 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
13 rules| Detection | Severity | Format |
|---|---|---|
| Attacker Tools On Endpoint | Undefined | SPL |
| Cisco SA - Automated Web Reconnaissance via HTTP Access Errors | Undefined | SPL |
| Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication | Undefined | SPL |
| Cisco SD-WAN Multiple SSH key Authentication from Same Source | Undefined | SPL |
| Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity | Undefined | SPL |
| Cisco Secure Firewall - Blocked Connection | Undefined | SPL |
| Cisco Secure Firewall - High Volume of Intrusion Events Per Host | Undefined | SPL |
| Cisco Secure Firewall - Repeated Blocked Connections | Undefined | SPL |
| HTTP Rapid POST with Mixed Status Codes | Undefined | SPL |
| Internal Vulnerability Scan | Undefined | SPL |
+ 3 more from splunk/security_content → showing the 10 highest-severity
panther-labs/panther-analysis
8 rules| Detection | Severity | Format |
|---|---|---|
| GSuite Government Backed Attack | Critical | Panther Python |
| GreyNoise V3 Malicious IP Activity | High | Panther Python |
| GTI/VirusTotal Threat Intelligence Indicator Match | High | Panther Python |
| OTX Threat Intelligence Indicator Match | High | Panther Python |
| Azure Excessive IP and VM Discovery | Medium | Panther Python |
| Azure Excessive Network Security Group Read | Medium | Panther Python |
| AWS WAF Managed Bot Control Passthrough Rule | Informational | Panther Python |
| AWS WAF Managed IP Reputation Passthrough Rule | Informational | Panther Python |
SigmaHQ/sigma
4 rules| Detection | Severity | Format |
|---|---|---|
| Grixba Malware Reconnaissance Activity | High | Sigma |
| PUA - PingCastle Execution From Potentially Suspicious Parent | High | Sigma |
| Potential Hello-World Scraper Botnet Activity | Medium | Sigma |
| PUA - PingCastle Execution | Medium | Sigma |
Wazuh Core Ruleset
3 rules| Detection | Severity | Format |
|---|---|---|
| from same source ip. | High | Wazuh XML |
| MS-DHCP: Packet dropped due to NAP policy. | High | Wazuh XML |
| Multiple web server 501 error code (Not Implemented). | High | Wazuh XML |
socfortress/Wazuh-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · Wordlist Scanning with PowerShell (T1595.003) | High | Wazuh XML |
| Possible wordlist scanning based on known filename patterns (T1595.003) | Medium | Wazuh XML |
| Wordlist scanning tool execution detected (T1595.003) | Medium | Wazuh XML |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Detect Enumeration Activity Using Unique Identifiers and Session Aggregation | Undefined | KQL |