T1046 Network Service Discovery — ATT&CK Technique
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well. Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.
Detection coverage (31)
- Pnscan Binary Data Transmission Activity medium
- Grixba Malware Reconnaissance Activity high
- OpenCanary - Host Port Scan (SYN Scan) high
- OpenCanary - NMAP XMAS Scan high
- OpenCanary - NMAP FIN Scan high
- OpenCanary - NMAP NULL Scan high
- OpenCanary - NMAP OS Scan high
- Linux Network Service Scanning - Auditd low
- PUA - Advanced IP Scanner Execution medium
- PUA - Advanced Port Scanner Execution medium
- Linux Network Service Scanning Tools Execution low
- PUA - NimScan Execution medium
- PUA - SoftPerfect Netscan Execution medium
- PUA - Nmap/Zenmap Execution medium
- MacOS Network Service Scanning low
- Advanced IP Scanner - File Event medium
- Python Initiated Connection medium
- HackTool - WinPwn Execution - ScriptBlock high
- HackTool - winPEAS Execution high
- HackTool - WinPwn Execution high
- Cisco IOS XE Remote Access Probe Burst
- Kubernetes Access Scanning
- Kubernetes Scanning by Unauthenticated IP Address
- Advanced IP or Port Scanner Execution
- Windows PsTools Recon Usage
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Repeated Blocked Connections
- Internal Vertical Port Scan
- Internal Horizontal Port Scan NMAP Top 20
- Internal Horizontal Port Scan
- Internal Vulnerability Scan
Malware using this technique
- Pupy
- Backdoor.Oldrea
- Industroyer
- Empire
- Ramsay
- HermeticWizard
- Royal
- SpeakUp
- BlackEnergy
- Hildegard
- NBTscan
- Peirates
- BADHATCH
- ZxShell
- Koadic
- China Chopper
- FRP
- SILENTTRINITY
- BlackByte Ransomware
- Xbash
- Cobalt Strike
- PoshC2
- Brute Ratel C4
- P.A.S. Webshell
- XTunnel
- Remsec
- MgBot
- LightSpy
- Conficker
- Lucifer
- HDoor
- MURKYTOP
- InvisiMole
- Caterpillar WebShell
- Pysa