Network Service Discovery T1046

Tactic: Discovery

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Events covered

18 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 101 rules share fields, values, and exclusions.

Fields filtered most (138 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name18in 8, regex_match 8, eq 2, wildcard 1(?i)\x5cnetscan(32|64)?\.exe, (?i)\x5cnetscan_portable, (?i)advanced_ip_scanner, (?i)advanced_port_scanner\.exe, (?i)masscan\.exe
EventType17in 9, eq 8exec, exec_event, ProcessRollup2, connection_attempted, flow_started
src_ip17is_not_null 6, eq 5, in 5, cidr_match 1, regex_match 110.0.0.0/8, %vulnerability_scanners%, 127.0.0.1, 172.16.0.0/12, 192.168.0.0/16
CommandLine15contains 10, regex_match 5, ends_with 1(?i)\sportable/s.+\slng, (?i)ping\s+-n\s1\s-w\s1\s(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-..., /lng, /portable, --listen
EventID13eq 134688, 1, 4103, 4104, 5152
event.type10eq 10start
host.os.type10eq 10
DestinationPort9is_not_null 5, in 2, lt 1, regex_match 1110, 111, 135, 139, 21
Image9ends_with 6, contains 3.exe, /autorecon, /hping, /hping2, /nc
Type7eq 7AwsEc2SecurityGroup
OriginalFileName6contains 2, eq 2, in 2advanced_ip_scanner, advanced_ip_scanner.exe, advanced_ip_scanner_console.exe, advanced_port_scanner, advanced_port_scanner.exe
logtype5eq 55001, 5002, 5003, 5004, 5005
Action4eq 4Deny, Allowed, Blocked, Matched
OperationName4eq 3, in 1AzureFirewallApplicationRuleLog, AzureFirewallNetworkRuleLog
Description3contains 2, eq 1advanced ip scanner, advanced port scanner, application for scanning networks

Top indicator values (1015 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
101078
EventIDeq
4688
6317
EventIDeq
1
5241
EventTypein
exec
5201
EventTypein
exec_event
5149
EventTypein
start
5163
EventTypein
ProcessRollup2
4117
EventTypein
executed
498
EventTypein
process_started
483
EventTypein
flow_started
33
EventTypein
network_flow
33
src_ipin
10.0.0.0/8
516
src_ipin
172.16.0.0/12
516
src_ipin
192.168.0.0/16
516
src_ipeq
%vulnerability_scanners%
4
src_ipeq
127.0.0.1
46
src_ipeq
::1
37
EventTypeeq
exec
3576
LogonTypeeq
Network
341
OperationNameeq
AzureFirewallApplicationRuleLog
34
OperationNameeq
AzureFirewallNetworkRuleLog
33
process_namein
nc
324
process_namein
ncat
325
process_namein
netcat
324
process_namein
socat
316
Actioneq
Deny
22
CommandLinecontains
/lng
22
CommandLinecontains
/portable
22
CommandLineregex_match
(?i)\sportable/s.+\slng
22
CommandLineregex_match
(?i)ping\s+-n\s1\s-w\s1\s(10\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}|172\.(1[6-9]...
22

Exclusions (144 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipeq
%vulnerability_scanners%
4
src_ipeq
127.0.0.1
4
src_ipeq
::1
3
DestinationPortin
443
3
DestinationPortin
80
3
DestinationPortin
0
2
DestinationPortin
389
2
DestinationPortin
53
2
DestinationPortin
8080
2
DestinationPortin
880
2
DestinationPortin
8888
2
Reasoncontains
aged-out
2
Reasoncontains
tcp-fin
2
TotalEventsgt
25
2
process.argswildcard
-*z*
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 24 rules

Elastic 20 rules

Splunk 25 rules

Kusto 26 rules

Panther 6 rules