Skip to content
Threat Feed

Tag

Reconnaissance

69 briefs RSS
low advisory

Detection of External IP Discovery via Curl on macOS

Threat actors utilize curl or nscurl on macOS to query public IP geolocation services for reconnaissance, enabling them to assess network context and stage follow-on malicious activity.

macos discovery reconnaissance
1r 1t 1i
high advisory

Suspicious Windows Public IP Address Discovery via DNS

Adversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.

discovery c2 windows reconnaissance
1r 1t 33i
medium advisory

Sensitive File Compression Detected in Linux Containers for Credential Access

Elastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.

Defend for Containers container linux credential-access data-collection threat-detection discovery reconnaissance network-scanning +6
3r 8t 1i
low advisory

Unusual Linux Process Discovery Activity

An Elastic machine learning rule detects unusual Linux process discovery activity from atypical user contexts, indicating a potentially compromised account performing reconnaissance for privilege escalation or persistence on Linux systems.

endpoint linux elastic-defend auditd-manager threat-detection ml machine-learning discovery +1
1t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
medium advisory

Malware Employs Web Services for Victim IP Reconnaissance

Malware, including Trickbot and various stealers, utilizes DNS queries to public IP checking web services for reconnaissance purposes, aiming to determine the victim's external IP address, which can facilitate further attacks or lateral movement.

reconnaissance malware dns-query windows
1r 1t 27i
medium advisory

Anti-Virus Product Reconnaissance via PowerShell or WMI

This brief details the detection of suspicious PowerShell script execution that targets the discovery of installed anti-virus and anti-spyware products using WMI or PowerShell commands, a common reconnaissance tactic employed by malicious actors to map security applications and potentially evade defenses.

reconnaissance discovery defense-evasion powershell wmi endpoint
1r 1t
high advisory

Server-Side Request Forgery in Huginn (CVE-2026-63769)

A server-side request forgery vulnerability, CVE-2026-63769, in Huginn through version 2022.08.18 allows authenticated users to make arbitrary HTTP requests via crafted URLs, leading to internal network probing, port enumeration, and potential credential theft from cloud metadata endpoints.

Huginn server-side-request-forgery web-vulnerability cve reconnaissance credential-access
1r 2t 1c
low advisory

AWS S3 Rapid Bucket Posture API Calls from a Single Principal

This detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.

S3 +1 aws cloudtrail discovery collection reconnaissance cloud
4t
low advisory

AWS Account Discovery By Rare User

A new detection rule identifies rare instances where an identity performs AWS Organizations or IAM account enumeration APIs for the first time within a specified lookback window, indicative of an attacker attempting to map the AWS environment after compromising credentials.

AWS Organizations +1 cloud aws discovery identity reconnaissance
1r 2t
low advisory

AWS CLI Discovery from Single Resource

An Elastic detection rule identifies when a single AWS identity, using the AWS CLI, performs more than five distinct read-only discovery API calls (such as Describe*, List*, Get*, and Generate*) across various AWS services within a 10-second window, indicating reconnaissance by an adversary using compromised credentials or an exploited EC2 instance to map the AWS infrastructure for potential targets and further exploitation.

AWS +13 cloud discovery reconnaissance cli
2t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
low advisory

Webshell Reconnaissance Command Detection

This brief describes detection of common reconnaissance commands executed through webshells on Windows systems, enabling defenders to identify post-exploitation discovery activities.

webshell discovery reconnaissance attack.persistence attack.discovery attack.t1505.003 attack.t1018 attack.t1033 +1
1r 10t 1c
low advisory

macOS Local System Accounts Discovery

Adversaries leverage various built-in macOS utilities and commands, such as `dscl`, `dscacheutil`, `cat /etc/passwd`, `id`, `lsof`, `who`, `w`, `users`, `last`, `ls /Users`, `defaults`, and `plutil`, to enumerate local system accounts, facilitating lateral movement or privilege escalation within a compromised macOS environment.

macOS discovery reconnaissance
1r 1t
low advisory

Linux External IP Discovery via Curl

This brief details the detection of Linux processes utilizing `curl` to contact known public IP address lookup web services, a common post-exploitation technique employed by malware and adversaries to ascertain a host's internet-facing IP, impacting reconnaissance and command-and-control tailoring.

discovery linux endpoint reconnaissance curl
1r 1t 38i
low advisory

ICMP Timestamp or Information Request from the Internet

This brief identifies inbound ICMP Timestamp (type 13) or Information (type 15) requests originating from external IP addresses and targeting internal RFC1918 destinations, a legacy diagnostic activity commonly associated with host and path fingerprinting during reconnaissance, active scanning, or OS fingerprinting efforts by an unidentified actor, indicating a potential prelude to more severe attacks.

network_traffic integration network discovery reconnaissance icmp elastic
1r 2t
high advisory

Web Server Potential SQL Injection Attempt Detection

This brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.

Apache +5 sql-injection web-attack reconnaissance initial-access data-exfiltration command-execution persistence cross-platform
1r 6t
low advisory

Linux External IP Address Discovery via Curl

Malware and threat actors on Linux systems utilize the `curl` command to query public web services for external IP address discovery, a reconnaissance technique (T1016) that can precede further C2 establishment or targeted attacks.

Elastic Defend +1 discovery linux reconnaissance
1r 1t 38i
medium advisory

WMIC Remote Command Execution Detection

This brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.

lateral-movement reconnaissance execution wmic windows
1r 1t
medium threat

System Disk And Volume Reconnaissance Via Wmic.EXE

Threat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.

Volt Typhoon +3 discovery reconnaissance wmic living-off-the-land windows
1r 2t
medium advisory

Potential Unquoted Service Path Reconnaissance Via Wmic.EXE

Attackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.

reconnaissance privilege-escalation windows wmic
1r 2t 1c
medium threat

Uncommon WMIC System Information Discovery by Aurora Stealer

Aurora Stealer has been observed using the Windows Management Instrumentation Command-line (WMIC) utility to perform extensive system reconnaissance, gathering details like OS version, CPU, GPU, disk drives, memory, and display resolution, indicating early-stage information gathering for subsequent data exfiltration or malware deployment.

Windows Aurora Stealer reconnaissance discovery infostealer
1r 1t
medium advisory

Service Reconnaissance Via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.

Windows Operating System windows reconnaissance wmic internal-recon
1r 1t
medium advisory

Potential Product Class Reconnaissance Via Wmic.EXE

Adversaries are leveraging `wmic.exe` on Windows systems to perform reconnaissance, specifically enumerating installed antivirus, antispyware, and firewall products to aid in evasion and subsequent attack planning, posing a medium risk to affected organizations.

reconnaissance discovery windows
1r 2t
medium advisory

WMIC Product Reconnaissance for Defense Evasion

A threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.

reconnaissance defense-evasion windows wmic
1r 2t
medium advisory

Potential Process Reconnaissance via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility with the 'process' flag to perform discovery of running processes on compromised systems, enabling further stages of attack such as privilege escalation or lateral movement.

reconnaissance discovery windows
1r 2t
medium advisory

Windows Hotfix Updates Reconnaissance Via Wmic.EXE

Attackers and pentesters utilize `wmic.exe` with the 'qfe' flag to enumerate installed hotfix updates on Windows systems, a common reconnaissance technique often preceding privilege escalation.

reconnaissance privilege-escalation windows attack.execution attack.t1047
1r 1t
low advisory

Detect Local Groups Reconnaissance Using WMIC

Adversaries utilize the legitimate Windows Management Instrumentation Command-line (WMIC) tool, specifically `wmic.exe group`, to perform reconnaissance on local system groups and identify users with elevated permissions on targeted Windows systems.

windows reconnaissance discovery
1r 1t
medium threat

Hardware Model Reconnaissance Via Wmic.EXE

Adversaries leverage the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility with the `csproduct` command to perform hardware model and vendor reconnaissance on target systems, a technique observed in campaigns utilizing infostealers like Kuraystealer, enabling further tailored attacks.

Kuraystealer reconnaissance windows infostealer
1r 6t
medium threat

Computer System Reconnaissance Via Wmic.EXE

This brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.

Windows DEV-0270 +5 discovery reconnaissance ransomware
1r 1t
low advisory

Local Account and System Owner Discovery via Native Utilities

Threat actors utilize built-in Windows utilities like whoami, wmic, and net to perform local account and system owner discovery, a common post-exploitation reconnaissance technique facilitating privilege escalation and lateral movement.

discovery reconnaissance post-exploitation windows
1r 2t
medium advisory

Suspicious User-Agents Related To Recon Tools

This brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.

reconnaissance web-security attack.initial-access attack.t1190
1r 3t
high advisory

SQL Server Critical Procedures Enabled Leading to Potential Code Execution or Reconnaissance

Modification of critical SQL Server configuration options, such as 'Ad Hoc Distributed Queries', 'external scripts enabled', 'Ole Automation Procedures', 'clr enabled', and 'clr strict security', can enable attackers to perform Active Directory reconnaissance and execute arbitrary code, potentially leading to code execution or reconnaissance activities.

SQL Server +3 sql-server code-execution reconnaissance windows
2r 2t
medium advisory

Threat Actors Use Claude AI to Target Water Utility OT Assets

An unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.

AI OT SCADA password-spraying reconnaissance
2r 2t
low advisory

Rapid Enumeration of AWS S3 Buckets

An AWS principal rapidly enumerates S3 bucket posture using read-only APIs, indicative of reconnaissance, scanning, or post-compromise activity.

AWS S3 +1 aws s3 cloudtrail discovery enumeration reconnaissance
2r 4t
low advisory

AWS S3 Rapid Bucket Posture API Calls Indicate Reconnaissance

An AWS principal rapidly enumerates S3 bucket configurations using read-only APIs, potentially indicating reconnaissance activity by security scanners, CSPM tools, or malicious actors performing post-compromise enumeration.

cloud aws s3 reconnaissance
2r 4t
high advisory

OpenCanary Telnet Login Attempt

The OpenCanary Telnet Login Attempt detection identifies unauthorized login attempts to a Telnet service monitored by an OpenCanary node, indicating potential reconnaissance or intrusion attempts targeting the network.

honeypot telnet reconnaissance intrusion opencanary
1r 2t
high advisory

OpenCanary SSH Connection Attempt

An SSH connection attempt to an OpenCanary node indicates a potential adversary probing for vulnerable services or attempting unauthorized access within a network.

OpenCanary honeypot ssh reconnaissance
2r 1t
high advisory

Detecting Pre-Ransomware Active Directory Reconnaissance

Adversaries perform Active Directory reconnaissance using built-in tools like nltest, whoami, and net.exe to map the environment before deploying ransomware.

Active Directory active-directory reconnaissance ransomware
3r 2t
high advisory

BloodHound Data Collection Activity

Adversaries may use the SharpHound tool to collect Active Directory data, saving it into default JSON files for BloodHound analysis, potentially leading to privilege escalation or lateral movement.

Active Directory bloodhound active-directory reconnaissance privilege-escalation
2r 6t
medium advisory

AdFind.exe Execution with Reconnaissance Arguments

This rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.

AdFind +2 Conti +3 active-directory reconnaissance discovery
2r 1t 1i
low threat

AdFind Active Directory Reconnaissance Activity

AdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.

Active Directory Trickbot +3 adfind active-directory reconnaissance discovery windows
3r 5t
low advisory

Web Server Error Response Spike Indicating Reconnaissance

An unusual spike in web server error codes (500, 502, 503, 504) may indicate reconnaissance activities like vulnerability scanning or fuzzing, where attackers probe for weaknesses, potentially leading to exploitation of server-side issues.

Nginx +4 web-server reconnaissance vulnerability-scanning fuzzing
2r 2t
medium advisory

ESXi System Information Discovery via ESXCLI

Adversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.

ESXi reconnaissance vmware
2r 1t
low advisory

Rapid Enumeration of AWS S3 Buckets via API Calls

An AWS principal from a single source IP rapidly invokes read-only S3 control-plane APIs, revealing bucket posture across many buckets in a short time, potentially indicating automated reconnaissance or post-compromise enumeration.

Amazon S3 aws cloudtrail s3 reconnaissance
2r 4t
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
medium advisory

Cisco ASA Device File Copy Activity

Adversaries may copy device files, including configurations and packet captures, from Cisco ASA devices via CLI or ASDM for reconnaissance, credential extraction, or data exfiltration, which can be detected via command execution logs.

Cisco ASA +1 cisco asa file_copy reconnaissance credential_access exfiltration
2r 2t
medium advisory

AWS IAM Access Denied Discovery Events

This detection identifies potential reconnaissance activity by an attacker attempting to discover AWS IAM permissions and configurations by generating a high volume of access denied events.

AWS IAM cloud aws iam reconnaissance
2r 1t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

Windows EventLog Reconnaissance Activity Detection

This detection identifies potential reconnaissance activities on Windows systems by adversaries using tools like `wevtutil.exe`, `wmic.exe`, and PowerShell cmdlets to query event logs for sensitive information.

Windows eventlog reconnaissance
3r 1t
medium advisory

Suspicious WMI Reconnaissance via PowerShell

This analytic detects suspicious PowerShell activity leveraging WMI to gather system information, potentially indicating reconnaissance by an attacker.

Windows reconnaissance powershell wmi
2r 2t
medium advisory

Unsecured Elasticsearch Node Inbound Connection

This rule identifies potentially unsecured Elasticsearch nodes that lack TLS and/or authentication and are accepting inbound network connections, which could allow adversaries to gain initial access, exfiltrate data, or disrupt services.

Elasticsearch initial-access reconnaissance network
2r 2t
medium advisory

Kubernetes Multi-Resource Discovery Reconnaissance

Adversaries may perform reconnaissance in a Kubernetes environment by rapidly querying multiple resource types to map the environment and identify potential privilege escalation paths.

Kubernetes discovery reconnaissance
2r 1t
medium advisory

Windows Software Discovery via PowerShell Registry Queries

Attackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.

Splunk Enterprise +2 software-discovery powershell registry reconnaissance
2r 3t
low advisory

Web Server Reconnaissance via Unusual User Agents

Detection of unusual spikes in web server requests with uncommon or suspicious user-agent strings indicative of reconnaissance attempts to identify web application vulnerabilities or brute-force attacks.

Nginx +4 web-server reconnaissance vulnerability-scanning user-agent
2r 4t
medium advisory

Linux System Network Discovery via Multiple Utilities

Adversaries may attempt to enumerate local network configurations on Linux systems using common utilities like arp, ifconfig, ip, netstat, firewall-cmd, ufw, iptables, ss, and route to gather information for reconnaissance and subsequent attacks, leading to network mapping and vulnerability identification.

Linux network-discovery reconnaissance
2r 1t
medium advisory

Detection of Obfuscated IP Addresses via Command Line Tools

The use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.

Windows reconnaissance evasion command-line
3r 1t
medium advisory

Cisco ASA Reconnaissance Command Activity

This analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.

Cisco ASA cisco reconnaissance network
2r 3t
medium advisory

AWS Excessive Security Scanning Detection

Detection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.

AWS cloudtrail reconnaissance
2r 1t
low advisory

Active Directory Discovery via ADExplorer Execution

Detects the execution of ADExplorer, a tool used for Active Directory viewing and editing, which can be abused by adversaries for domain reconnaissance and creating offline snapshots of the AD database.

Microsoft Defender XDR +1 active-directory discovery reconnaissance windows
2r 5t
medium advisory

High Number of AWS Bedrock List Foundation Model Failures

Detection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.

Bedrock aws reconnaissance cloudtrail
2r 1t
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detected

Detection of web server discovery or fuzzing activity indicated by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, suggesting attempts to discover hidden resources.

Nginx +4 web-server fuzzing reconnaissance web-application
2r 2t
low advisory

Web Server Discovery or Fuzzing Activity

Detection of potential web server discovery or fuzzing activity characterized by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, indicating attackers are probing for hidden resources.

Nginx +4 reconnaissance web-server fuzzing
2r 2t
medium advisory

Suspicious Enumeration Commands Spawned via WMIPrvSE

This rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.

Windows enumeration wmi reconnaissance
2r 13t
medium advisory

macOS DNS Request for IP Lookup Service via Unsigned Binary

An unsigned or untrusted binary on macOS is performing DNS requests for IP lookup services to determine the system's external IP address, which is commonly used by malware for reconnaissance before establishing C2 connections.

macOS discovery dns reconnaissance unsigned_binary
2r 1t 42i
medium advisory

Kubernetes Access Scanning Detection

This analytic detects potential reconnaissance activities within a Kubernetes environment by identifying repeated failed access attempts or unusual API requests from unauthenticated users based on Kubernetes audit logs, indicating a potential attacker's preliminary reconnaissance.

Kubernetes scanning reconnaissance
2r 1t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
low threat

AdFind Tool Used for Active Directory Reconnaissance

The execution of AdFind.exe, an Active Directory query tool, is often used by threat actors for post-exploitation Active Directory reconnaissance, as observed in campaigns involving Trickbot, Ryuk, Maze, and FIN6.

Elastic Defend FIN6 adfind active-directory reconnaissance windows
2r 5t