Active Scanning T1595
Tactic: Reconnaissance
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 3 | Network connection |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 73 rules share fields, values, and exclusions.
Fields filtered most (122 distinct)
These fields appear most often in rule filters.
Top indicator values (749 distinct)
These values appear most often in rule predicates.
Exclusions (55 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 5 rules
- DNS Query to External Service Interaction Domains
- Grixba Malware Reconnaissance Activity
- Potential Hello-World Scraper Botnet Activity
- PUA - PingCastle Execution
- PUA - PingCastle Execution From Potentially Suspicious Parent
Elastic 20 rules
- GKE Anonymous Endpoint Permission Enumeration
- ICMP Timestamp or Information Request from the Internet
- Inbound Connection to an Unsecure Elasticsearch Node
- Kubernetes Potential Endpoint Permission Enumeration Attempt by Anonymous User Detected
- Potential Linux Hack Tool Launched
- Potential Network Scan Detected
- Potential Network Sweep Detected
- Potential SIP Extension Enumeration
- Potential Spike in Web Server Error Logs
- Potential SYN-Based Port Scan Detected
- Spike in Firewall Denies
- Spike in Network Traffic
- Spike in Network Traffic To a Country
- Suspicious Network Tool Launch Detected via Defend for Containers
- Suspicious Network Tool Launched Inside A Container
- Web Server Discovery or Fuzzing Activity
- Web Server Potential Command Injection Request
- Web Server Potential Spike in Error Response Codes
- Web Server Potential SQL Injection Request
- Web Server Suspicious User Agent Requests
Splunk 13 rules
- Attacker Tools On Endpoint
- Cisco SA - Automated Web Reconnaissance via HTTP Access Errors
- Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity
- Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication
- Cisco SD-WAN Multiple SSH key Authentication from Same Source
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host
- Cisco Secure Firewall - Repeated Blocked Connections
- HTTP Rapid POST with Mixed Status Codes
- Internal Vulnerability Scan
- Ollama Possible API Endpoint Scan Reconnaissance
- Windows Detect Network Scanner Behavior
- Windows Netspy Network Scanner Execution
Kusto 27 rules
- API - Kiterunner detection
- App Gateway WAF - Scanner Detection
- AWSCloudTrail - Suspicious AWS CLI Command Execution
- BitSight - diligence risk category detected
- Claroty - Threat detected
- Dataverse - Suspicious use of Web API
- Disks Alerts From Prancer
- Flow Logs Alerts for Prancer
- GTI Relevance System Alert - Incident by Alert ID
- NetworkSecurityGroups Alert From Prancer
- OCI - Multiple rejects on rare ports
- OCI - SSH scanner
- PAC high severity
- Palo Alto - possible nmap scan on with top 100 option
- PaloAlto - Possible port scan
- Port Scan
- Port Sweep
- Registries Alerts for Prancer
- SAP BTP - Failed access attempts across multiple BAS subaccounts
- Sites Alerts for Prancer
- Storage Accounts Alerts From Prancer
- Subnets Alerts for Prancer
- UniFi Site Manager: Pending firmware updates outstanding for 7d+
- Vaults Alerts for Prancer
- Virtual Machines Alerts for Prancer
- VirtualNetworkPeerings Alerts From Prancer
- XbowNewAssetDiscovered
Panther 8 rules
- AWS WAF Managed Bot Control Passthrough Rule
- AWS WAF Managed IP Reputation Passthrough Rule
- Azure Excessive IP and VM Discovery
- Azure Excessive Network Security Group Read
- GreyNoise V3 Malicious IP Activity
- GSuite Government Backed Attack
- GTI/VirusTotal Threat Intelligence Indicator Match
- OTX Threat Intelligence Indicator Match