EXPLORE
← Back to Explore
T1595

Active Scanning

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction. Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols...

PRE
26
Detections
4
Sources
0
Threat Actors

BY SOURCE

16elastic5splunk_escu3sigma2crowdstrike_cql

PROCEDURES (15)

Network Connection Monitoring4 detections

Auto-extracted: 4 detections for network connection monitoring

Service3 detections

Auto-extracted: 3 detections for service

Dump2 detections

Auto-extracted: 2 detections for dump

Unusual2 detections

Auto-extracted: 2 detections for unusual

C22 detections

Auto-extracted: 2 detections for c2

Process Creation Monitoring1 detections

Auto-extracted: 1 detections for process creation monitoring

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Http1 detections

Auto-extracted: 1 detections for http

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

Authentication Monitoring1 detections

Auto-extracted: 1 detections for authentication monitoring

DETECTIONS (26)