Gather Victim Network Information T1590
Tactic: Reconnaissance
Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP ranges, domain names, etc.) as well as specifics regarding its topology and operations.
Events covered
13 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 18 rules share fields, values, and exclusions.
Fields filtered most (27 distinct)
These fields appear most often in rule filters.
Top indicator values (223 distinct)
These values appear most often in rule predicates.
Exclusions (88 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 4 rules
- Failed DNS Zone Transfer
- PUA - Advanced IP/Port Scanner Update Check
- PUA - Crassus Execution
- Suspicious DNS Query for IP Lookup Service APIs
Elastic 1 rule
Splunk 8 rules
- Cisco ASA - Reconnaissance Command Activity
- Cisco IOS XE Reconnaissance Command Activity
- Cisco NVM - Suspicious Network Connection to IP Lookup Service API
- Local LLM Framework DNS Query
- Wermgr Process Connecting To IP Check Web Services
- Windows DNS Gather Network Info
- Windows Gather Victim Network Info Through Ip Check Web Services
- Windows WinPEAS PowerShell Script Execution
Kusto 5 rules
- AWSCloudTrail - Suspicious AWS CLI Command Execution
- Network Port Sweep from External Network (ASIM Network Session schema)
- Rare client observed with high reverse DNS lookup count - Anomaly based (ASIM DNS Solution)
- Rare client observed with high reverse DNS lookup count - Static threshold based (ASIM DNS Solution)
- UniFi Site Manager: External WAN IP changed