Network Service Discovery T1046
Tactic: Discovery
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Events covered
18 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 101 rules share fields, values, and exclusions.
Fields filtered most (138 distinct)
These fields appear most often in rule filters.
Top indicator values (1015 distinct)
These values appear most often in rule predicates.
Exclusions (144 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 24 rules
- Advanced IP Scanner - File Event
- Anonymous access performed to multiple targets
- Grixba Malware Reconnaissance Activity
- HackTool - winPEAS Execution
- HackTool - WinPwn Execution
- HackTool - WinPwn Execution - ScriptBlock
- Linux Network Service Scanning - Auditd
- Linux Network Service Scanning Tools Execution
- MacOS Network Service Scanning
- Network login performed to multiple targets
- OpenCanary - Host Port Scan (SYN Scan)
- OpenCanary - NMAP FIN Scan
- OpenCanary - NMAP NULL Scan
- OpenCanary - NMAP OS Scan
- OpenCanary - NMAP XMAS Scan
- Pnscan Binary Data Transmission Activity
- PUA - Advanced IP Scanner Execution
- PUA - Advanced Port Scanner Execution
- PUA - NimScan Execution
- PUA - Nmap/Zenmap Execution
- PUA - SoftPerfect Netscan Execution
- Python Initiated Connection
- RDP discovery performed on multiple hosts
- Suspicious anonymous login (domain specified)
Elastic 20 rules
- DNS Enumeration Detected via Defend for Containers
- Hping Process Activity
- Nping Process Activity
- Potential Linux Hack Tool Launched
- Potential Network Scan Detected
- Potential Network Scan Executed From Host
- Potential Network Sweep Detected
- Potential Port Scanning Activity from Compromised Host
- Potential PowerShell HackTool Script by Function Names
- Potential SIP Extension Enumeration
- Potential Subnet Scanning Activity from Compromised Host
- Potential SYN-Based Port Scan Detected
- Potentially Suspicious Process Started via tmux or screen
- Spike in Firewall Denies
- Spike in host-based traffic
- Spike in Network Traffic
- Spike in Network Traffic To a Country
- Suricata and Elastic Defend Network Correlation
- Suspicious Network Tool Launch Detected via Defend for Containers
- Suspicious Network Tool Launched Inside A Container
Splunk 25 rules
- Advanced IP or Port Scanner Execution
- Advanced IP Scanner Execution (Sysmon)
- Advanced IP Scanner Execution (Windows Event Log)
- Advanced Port Scanner Execution (Sysmon)
- Advanced Port Scanner Execution (Windows Event Log)
- Cisco IOS XE Remote Access Probe Burst
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Repeated Blocked Connections
- FScan.exe Network Scan (Sysmon)
- FScan.exe Network Scan (Windows Event Log)
- Internal Horizontal Port Scan
- Internal Horizontal Port Scan NMAP Top 20
- Internal Port Scan - Critical Ports (Windows Event Log)
- Internal Vertical Port Scan
- Internal Vulnerability Scan
- Kubernetes Access Scanning
- Kubernetes Scanning by Unauthenticated IP Address
- List Open Egress Ports (Sysmon)
- List Open Egress Ports (Windows Event Log)
- masscan Execution - Windows (PowerShell)
- masscan Execution - Windows (Sysmon)
- masscan Execution - Windows (Windows Event Log)
- SoftPerfect Network Scanner Execution (Sysmon)
- SoftPerfect Network Scanner Execution (Windows Event Log)
- Windows PsTools Recon Usage
Kusto 26 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- Abnormal Deny Rate for Source IP
- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- App Gateway WAF - Scanner Detection
- AWS Security Hub - Detect EC2 Security groups allowing unrestricted high-risk ports
- Cisco ASA - average attack detection rate increase
- Cisco ASA - threat detection message fired
- Cisco Cloud Security - Hack Tool User-Agent Detected
- CloudNGFW By Palo Alto Networks - possible internal to external port scanning
- CloudNGFW By Palo Alto Networks - Threat signatures from Unusual IP addresses
- Cross-Cloud Suspicious user activity observed in GCP Envourment
- GCP Security Command Center - Detect Firewall rules allowing unrestricted high-risk ports
- GSA - Detect Source IP Scanning Multiple Open Ports
- Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports)
- Network Port Sweep from External Network (ASIM Network Session schema)
- Palo Alto - possible internal to external port scanning
- Palo Alto Threat signatures from Unusual IP addresses
- Port Scan
- Port Scan Detected
- Port scan detected (ASIM Network Session schema)
- Port Sweep
- Powershell Empire Cmdlets Executed in Command Line
- Rare client observed with high reverse DNS lookup count
- Several deny actions registered
- Tailscale Premium: Mass fan-out from single node
- Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host