Skip to content
Threat Feed

Tag

Reconnaissance

103 briefs RSS
low advisory

Detection of Web Server Reconnaissance via Error Log Spikes

This brief covers the detection of automated reconnaissance activities, such as vulnerability scanning and fuzzing, which manifest as significant spikes in web server error logs.

HTTP Server +2 reconnaissance web-security log-analysis
1r 3t
low advisory

Web Server Potential Command Injection via HTTP Requests

Threat actors are exploiting web application command injection vulnerabilities to execute arbitrary code by submitting crafted HTTP requests containing interpreter invocations, downloader utilities, or shell commands.

Nginx +4 command-injection web-shell web-application reconnaissance persistence execution
2t updated
medium advisory

Abuse of AWS Systems Manager Session Manager for Remote Execution

Adversaries abuse AWS Systems Manager (SSM) Session Manager to gain interactive shell access and perform remote command execution on EC2 instances or managed hybrid nodes.

AWS Systems Manager +1 cloud-security remote-execution lateral-movement cloud aws discovery reconnaissance
2r 5t updated
medium advisory

Virtual Machine Fingerprinting via Grep

Adversaries perform virtual machine fingerprinting by using grep to query hardware manufacturer identifiers, a technique used by malware like Pupy RAT for sandbox and virtualization evasion.

discovery defense-evasion sandbox-evasion reconnaissance
1r 2t
medium advisory

Detection of Security Software Discovery via Grep on macOS and Linux

Attackers utilize standard command-line tools like grep and pgrep to enumerate installed security software on macOS and Linux, enabling situational awareness for post-compromise activity.

discovery macos linux e-dr reconnaissance
1r 1t
medium threat

Detection of sqlmap Automated Tool Usage via User-Agent

This brief covers the detection of the sqlmap automated penetration testing tool, which is frequently used by adversaries to perform reconnaissance and exploit SQL injection vulnerabilities in web applications.

exploited reconnaissance vulnerability-scanning web-application apm sqlmap
1r 1t
medium advisory

Detection of Potential Linux Hack Tool Execution

Adversaries leverage common security assessment and exploitation tools on Linux hosts to perform reconnaissance, credential access, and vulnerability exploitation, necessitating a baseline of authorized administrative activities.

linux execution reconnaissance credential-access
1r 2t
medium advisory

Detection of Newly Observed Legitimate Network Scanning Tools

Adversaries frequently utilize legitimate network scanning utilities like SoftPerfect Network Scanner and Advanced IP Scanner for reconnaissance following initial compromise to map internal network topology and identify lateral movement targets.

SoftPerfect Network Scanner +2 discovery reconnaissance windows endpoint-detection
1r 2t updated
high advisory

Generative Threat Groups Automating Cyber Operations with AI

Anthropic has documented multiple threat actors leveraging AI models to automate end-to-end cyberattack workflows including reconnaissance, vulnerability research, credential harvesting, and large-scale data exfiltration.

AWS EC2 +2 ai-threat cyber-espionage surveillance reconnaissance data-exfiltration
3t
low advisory

Detection of SYN-Based Port Scanning Reconnaissance

Detection logic identifies internal reconnaissance activity characterized by a single source IP probing a large volume of unique destination ports using SYN packets.

reconnaissance discovery network-security port-scan
1r 2t
high advisory

Account Footprinting Vulnerability in GastroMenum Web Panel

GastroMenum Web Panel versions prior to 31.08.2026 contain an observable response discrepancy vulnerability enabling unauthorized account footprinting and user reconnaissance.

GastroMenum Web Panel reconnaissance web-vulnerability
1t 1c
high advisory

Unauthenticated SSRF in Openpanel Site Checker

Openpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.

Openpanel +2 web-vulnerability ssrf reconnaissance remote-code-execution injection privilege-escalation web-application cve-2026-88891 +3
1r 8t 1c updated
high advisory

Plaintext Password Storage Vulnerability in Menulux Portal

Menulux Portal versions before 20260903211448 contain a vulnerability that stores passwords in plaintext, potentially allowing unauthorized retrieval of sensitive credentials.

Menulux Portal reconnaissance vulnerability web-application
1t 1c
medium advisory

Suspicious PowerShell Reconnaissance and Data Export

Adversaries utilize automated PowerShell reconnaissance commands combined with redirection to temporary files to collect and stage system information for exfiltration.

collection powershell reconnaissance
1r 1t
medium advisory

Detection of Unconstrained Delegation Discovery via PowerShell

Adversaries are utilizing the Get-ADComputer PowerShell cmdlet to enumerate Active Directory objects configured for unconstrained delegation, a reconnaissance step often preceding ticket-based credential theft.

reconnaissance discovery active-directory powershell
1r 1t
medium advisory

Windows Screen Capture via PowerShell CopyFromScreen

Adversaries use the .NET CopyFromScreen method within PowerShell scripts to capture desktop screenshots for information gathering during post-compromise operations.

collection reconnaissance powershell endpoint-monitoring
1r 1t
medium advisory

Detection of Automated PowerShell Data Collection

Adversaries utilize automated PowerShell scripts to locate and gather sensitive documents across local file systems for subsequent exfiltration.

collection powershell reconnaissance
1r 1t
high advisory

Suspicious Reconnaissance Activity via GatherNetworkInfo.VBS

Adversaries are utilizing the native Windows script GatherNetworkInfo.vbs to perform system reconnaissance and collect network configuration data.

reconnaissance discovery lotl living-off-the-land windows-scripting
1r 2t
high advisory

Detection of PowerShell Get-Process Execution on LSASS

Adversaries may use PowerShell to enumerate the Local Security Authority Subsystem Service (LSASS) process as a precursor to credential dumping or process injection.

credential-access powershell reconnaissance
1r 1t
high advisory

Detection of Domain Controller Discovery via Nslookup

Adversaries utilize the nslookup utility to identify domain controllers through specific LDAP service record queries, a common step in network reconnaissance to facilitate domain-wide enumeration.

discovery reconnaissance active-directory windows
1r 2t
high advisory

Detection of BloodHound and SharpHound Enumeration Tools

Adversaries utilize BloodHound and SharpHound to perform automated reconnaissance and enumeration of Active Directory environments, facilitating lateral movement and privilege escalation.

reconnaissance active-directory windows hacktool
1r 1t
high advisory

Detection of PowerView Enumeration Framework Activity

PowerView is an open-source PowerShell module frequently used by threat actors for domain reconnaissance, user enumeration, and identifying lateral movement opportunities.

reconnaissance discovery post-exploitation powershell
1r 1t
high advisory

Sysmon Discovery via Driver Altitude Search

Adversaries use findstr.exe to identify the presence of Sysmon by searching for its default driver altitude, 385201, regardless of whether the service name has been altered.

discovery defense-evasion reconnaissance
1r 1t
medium advisory

Suspicious Group and Account Reconnaissance via Net.exe

Adversaries frequently use the Windows native 'net.exe' utility to perform discovery of privileged user groups and account configurations to facilitate lateral movement and privilege escalation.

discovery reconnaissance windows lateral-movement
1r 2t
medium advisory

Private Keys Reconnaissance Via Command Line Tools

Adversaries utilize native Windows utilities to enumerate local file systems for improperly stored private keys and cryptographic credentials.

credential-access reconnaissance
1r 1t
medium advisory

Security Software Discovery via PowerShell

Adversaries use PowerShell script blocks to enumerate active security software processes by filtering system process listings for known defensive product names and company identifiers.

discovery windows powershell reconnaissance
1r 1t
medium advisory

Detection of Network Connection Discovery via Arp.exe

Adversaries utilize the native Windows 'arp.exe' utility to perform network reconnaissance, mapping active hosts to facilitate lateral movement within compromised environments.

reconnaissance living-off-the-land discovery
1t
medium advisory

Concrete CMS IDOR Vulnerability in Conversation Rating Endpoint

Concrete CMS versions prior to 9.5.1 contain an IDOR vulnerability in the get_rating endpoint that allows unauthenticated attackers to enumerate message IDs and disclose rating data for private content.

Concrete Cms idor information-disclosure web-application reconnaissance
1r 1t 1c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
high advisory

Threat Actors Impersonate AI Crawlers to Exfiltrate Sensitive Credentials

Threat actors are using forged User-Agent strings to masquerade as AI crawlers from OpenAI, Anthropic, and other firms to scan for and exfiltrate environment files and cloud credentials from misconfigured web servers.

PoC Vite credential-theft web-scraping scanning reconnaissance
1r 2t 1c updated
high advisory

GCP Secret Manager Cross-Project Secret Enumeration

This threat brief details the detection of potential reconnaissance activity where an identity performs high-volume ListSecrets calls across multiple Google Cloud projects, a technique used for cloud service discovery.

Google Cloud Platform +1 cloud gcp reconnaissance discovery
1t
high advisory

Active Reconnaissance and Capability Development Against Siemens S7 PLCs

Threat actors are using AI-assisted scripts and the snap7 library to target Internet-exposed Siemens S7 Series PLCs for reconnaissance and potential operational disruption across critical infrastructure sectors.

S7-200 Series +4 ics ot reconnaissance siemens plc
2t
high advisory

City-Forum Campaign Targeting Salesforce and ServiceNow Guest Access

An unidentified threat actor is leveraging a custom multi-platform toolset to exploit misconfigured guest user permissions in Salesforce and ServiceNow, performing high-volume data enumeration and exfiltration.

Salesforce Aura +2 data-exfiltration cloud-security reconnaissance guest-access-abuse
2t 2i
medium advisory

Detection of Suspicious Dir Piped to Findstr Activity

Adversaries frequently leverage the 'dir' command piped to 'findstr' for reconnaissance to identify sensitive files and credentials on compromised Windows systems.

Windows discovery reconnaissance endpoint-security
1r 1t
low advisory

Detection of External IP Discovery via Curl on macOS

Threat actors utilize curl or nscurl on macOS to query public IP geolocation services for reconnaissance, enabling them to assess network context and stage follow-on malicious activity.

macos discovery reconnaissance
1r 1t 1i
high advisory

Suspicious Windows Public IP Address Discovery via DNS

Adversaries frequently use public IP lookup services to perform network reconnaissance and verify egress connectivity prior to establishing C2 channels, a behavior detectable via DNS query analysis from suspicious processes.

discovery c2 windows reconnaissance
1r 1t 33i
medium advisory

Sensitive File Compression Detected in Linux Containers for Credential Access

Elastic Defend for Containers detects the use of compression utilities like tar or zip within Linux containers to collect sensitive files such as SSH keys, AWS credentials, or system configurations, indicating potential credential access and data collection attempts by adversaries.

Defend for Containers container linux credential-access data-collection threat-detection discovery reconnaissance network-scanning +6
3r 8t 1i
low advisory

Unusual Linux Process Discovery Activity

An Elastic machine learning rule detects unusual Linux process discovery activity from atypical user contexts, indicating a potentially compromised account performing reconnaissance for privilege escalation or persistence on Linux systems.

endpoint linux elastic-defend auditd-manager threat-detection ml machine-learning discovery +1
1t
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
medium advisory

Malware Employs Web Services for Victim IP Reconnaissance

Malware, including Trickbot and various stealers, utilizes DNS queries to public IP checking web services for reconnaissance purposes, aiming to determine the victim's external IP address, which can facilitate further attacks or lateral movement.

reconnaissance malware dns-query windows
1r 1t 27i
medium advisory

Anti-Virus Product Reconnaissance via PowerShell or WMI

This brief details the detection of suspicious PowerShell script execution that targets the discovery of installed anti-virus and anti-spyware products using WMI or PowerShell commands, a common reconnaissance tactic employed by malicious actors to map security applications and potentially evade defenses.

reconnaissance discovery defense-evasion powershell wmi endpoint
1r 1t
high advisory

Server-Side Request Forgery in Huginn (CVE-2026-63769)

A server-side request forgery vulnerability, CVE-2026-63769, in Huginn through version 2022.08.18 allows authenticated users to make arbitrary HTTP requests via crafted URLs, leading to internal network probing, port enumeration, and potential credential theft from cloud metadata endpoints.

Huginn server-side-request-forgery web-vulnerability cve reconnaissance credential-access
1r 2t 1c
low advisory

AWS S3 Rapid Bucket Posture API Calls from a Single Principal

This detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.

S3 +2 aws cloudtrail discovery collection reconnaissance cloud
4t updated
low advisory

AWS Account Discovery By Rare User

A new detection rule identifies rare instances where an identity performs AWS Organizations or IAM account enumeration APIs for the first time within a specified lookback window, indicative of an attacker attempting to map the AWS environment after compromising credentials.

AWS Organizations +1 cloud aws discovery identity reconnaissance
1r 2t
low advisory

AWS CLI Discovery from Single Resource

An Elastic detection rule identifies when a single AWS identity, using the AWS CLI, performs more than five distinct read-only discovery API calls (such as Describe*, List*, Get*, and Generate*) across various AWS services within a 10-second window, indicating reconnaissance by an adversary using compromised credentials or an exploited EC2 instance to map the AWS infrastructure for potential targets and further exploitation.

AWS +13 cloud discovery reconnaissance cli
2t
high advisory

HelloNet Campaign Uses ViPNet Update System for Malicious Module Delivery

An unknown sophisticated threat actor is leveraging DLL sideloading within the ViPNet update system to deploy a multi-stage malware suite, including HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, and HelloBackdoor, to establish persistence, exfiltrate data, and maintain covert access to large Russian organizations in government, energy, and other critical sectors.

ViPNet Update System apt dll-sideloading persistence proxy c2 reconnaissance data-exfiltration russia +1
3r 11t 1i
low advisory

Webshell Reconnaissance Command Detection

This brief describes detection of common reconnaissance commands executed through webshells on Windows systems, enabling defenders to identify post-exploitation discovery activities.

webshell discovery reconnaissance attack.persistence attack.discovery attack.t1505.003 attack.t1018 attack.t1033 +1
1r 10t 1c
low advisory

macOS Local System Accounts Discovery

Adversaries leverage various built-in macOS utilities and commands, such as `dscl`, `dscacheutil`, `cat /etc/passwd`, `id`, `lsof`, `who`, `w`, `users`, `last`, `ls /Users`, `defaults`, and `plutil`, to enumerate local system accounts, facilitating lateral movement or privilege escalation within a compromised macOS environment.

macOS discovery reconnaissance
1r 1t
low advisory

Linux External IP Discovery via Curl

This brief details the detection of Linux processes utilizing `curl` to contact known public IP address lookup web services, a common post-exploitation technique employed by malware and adversaries to ascertain a host's internet-facing IP, impacting reconnaissance and command-and-control tailoring.

discovery linux endpoint reconnaissance curl
1r 1t 38i
low advisory

ICMP Timestamp or Information Request from the Internet

This brief identifies inbound ICMP Timestamp (type 13) or Information (type 15) requests originating from external IP addresses and targeting internal RFC1918 destinations, a legacy diagnostic activity commonly associated with host and path fingerprinting during reconnaissance, active scanning, or OS fingerprinting efforts by an unidentified actor, indicating a potential prelude to more severe attacks.

network_traffic integration network discovery reconnaissance icmp elastic
1r 2t
high advisory

Web Server Potential SQL Injection Attempt Detection

This brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.

Apache +5 sql-injection web-attack reconnaissance initial-access data-exfiltration command-execution persistence cross-platform
1r 6t
low advisory

Linux External IP Address Discovery via Curl

Malware and threat actors on Linux systems utilize the `curl` command to query public web services for external IP address discovery, a reconnaissance technique (T1016) that can precede further C2 establishment or targeted attacks.

Elastic Defend +1 discovery linux reconnaissance
1r 1t 38i
medium advisory

WMIC Remote Command Execution Detection

This brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.

lateral-movement reconnaissance execution wmic windows
1r 1t
medium threat

System Disk And Volume Reconnaissance Via Wmic.EXE

Threat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.

Volt Typhoon +3 discovery reconnaissance wmic living-off-the-land windows
1r 2t
medium advisory

Potential Unquoted Service Path Reconnaissance Via Wmic.EXE

Attackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.

reconnaissance privilege-escalation windows wmic
1r 2t 1c
medium threat

Uncommon WMIC System Information Discovery by Aurora Stealer

Aurora Stealer has been observed using the Windows Management Instrumentation Command-line (WMIC) utility to perform extensive system reconnaissance, gathering details like OS version, CPU, GPU, disk drives, memory, and display resolution, indicating early-stage information gathering for subsequent data exfiltration or malware deployment.

Windows Aurora Stealer reconnaissance discovery infostealer
1r 1t
medium advisory

Service Reconnaissance Via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.

Windows Operating System windows reconnaissance wmic internal-recon
1r 1t
medium advisory

Potential Product Class Reconnaissance Via Wmic.EXE

Adversaries are leveraging `wmic.exe` on Windows systems to perform reconnaissance, specifically enumerating installed antivirus, antispyware, and firewall products to aid in evasion and subsequent attack planning, posing a medium risk to affected organizations.

reconnaissance discovery windows
1r 2t
medium advisory

WMIC Product Reconnaissance for Defense Evasion

A threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.

reconnaissance defense-evasion windows wmic
1r 2t
medium advisory

Potential Process Reconnaissance via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility with the 'process' flag to perform discovery of running processes on compromised systems, enabling further stages of attack such as privilege escalation or lateral movement.

reconnaissance discovery windows
1r 2t
medium advisory

Windows Hotfix Updates Reconnaissance Via Wmic.EXE

Attackers and pentesters utilize `wmic.exe` with the 'qfe' flag to enumerate installed hotfix updates on Windows systems, a common reconnaissance technique often preceding privilege escalation.

reconnaissance privilege-escalation windows attack.execution attack.t1047
1r 1t
low advisory

Detect Local Groups Reconnaissance Using WMIC

Adversaries utilize the legitimate Windows Management Instrumentation Command-line (WMIC) tool, specifically `wmic.exe group`, to perform reconnaissance on local system groups and identify users with elevated permissions on targeted Windows systems.

windows reconnaissance discovery
1r 1t
medium threat

Hardware Model Reconnaissance Via Wmic.EXE

Adversaries leverage the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility with the `csproduct` command to perform hardware model and vendor reconnaissance on target systems, a technique observed in campaigns utilizing infostealers like Kuraystealer, enabling further tailored attacks.

Kuraystealer reconnaissance windows infostealer
1r 6t
medium threat

Computer System Reconnaissance Via Wmic.EXE

This brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.

Windows DEV-0270 +5 discovery reconnaissance ransomware
1r 1t
low advisory

Local Account and System Owner Discovery via Native Utilities

Threat actors utilize built-in Windows utilities like whoami, wmic, and net to perform local account and system owner discovery, a common post-exploitation reconnaissance technique facilitating privilege escalation and lateral movement.

discovery reconnaissance post-exploitation windows
1r 2t
medium advisory

Suspicious User-Agents Related To Recon Tools

This brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.

reconnaissance web-security attack.initial-access attack.t1190
1r 3t
high advisory

SQL Server Critical Procedures Enabled Leading to Potential Code Execution or Reconnaissance

Modification of critical SQL Server configuration options, such as 'Ad Hoc Distributed Queries', 'external scripts enabled', 'Ole Automation Procedures', 'clr enabled', and 'clr strict security', can enable attackers to perform Active Directory reconnaissance and execute arbitrary code, potentially leading to code execution or reconnaissance activities.

SQL Server +3 sql-server code-execution reconnaissance windows
2r 2t
medium advisory

Threat Actors Use Claude AI to Target Water Utility OT Assets

An unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.

AI OT SCADA password-spraying reconnaissance
2r 2t
low advisory

Rapid Enumeration of AWS S3 Buckets

An AWS principal rapidly enumerates S3 bucket posture using read-only APIs, indicative of reconnaissance, scanning, or post-compromise activity.

AWS S3 +1 aws s3 cloudtrail discovery enumeration reconnaissance
2r 4t
low advisory

AWS S3 Rapid Bucket Posture API Calls Indicate Reconnaissance

An AWS principal rapidly enumerates S3 bucket configurations using read-only APIs, potentially indicating reconnaissance activity by security scanners, CSPM tools, or malicious actors performing post-compromise enumeration.

cloud aws s3 reconnaissance
2r 4t
high advisory

OpenCanary Telnet Login Attempt

The OpenCanary Telnet Login Attempt detection identifies unauthorized login attempts to a Telnet service monitored by an OpenCanary node, indicating potential reconnaissance or intrusion attempts targeting the network.

honeypot telnet reconnaissance intrusion opencanary
1r 2t
high advisory

OpenCanary SSH Connection Attempt

An SSH connection attempt to an OpenCanary node indicates a potential adversary probing for vulnerable services or attempting unauthorized access within a network.

OpenCanary honeypot ssh reconnaissance
2r 1t
high advisory

Detecting Pre-Ransomware Active Directory Reconnaissance

Adversaries perform Active Directory reconnaissance using built-in tools like nltest, whoami, and net.exe to map the environment before deploying ransomware.

Active Directory active-directory reconnaissance ransomware
3r 2t
high advisory

BloodHound Data Collection Activity

Adversaries may use the SharpHound tool to collect Active Directory data, saving it into default JSON files for BloodHound analysis, potentially leading to privilege escalation or lateral movement.

Active Directory bloodhound active-directory reconnaissance privilege-escalation
2r 6t
medium advisory

AdFind.exe Execution with Reconnaissance Arguments

This rule detects the execution of AdFind.exe with specific command-line arguments used for reconnaissance, often associated with threat actors like Wizard Spider, FIN6, and groups linked to SUNBURST, who use it to enumerate domain controllers.

AdFind +2 Conti +3 active-directory reconnaissance discovery
2r 1t 1i
low threat

AdFind Active Directory Reconnaissance Activity

AdFind.exe, a legitimate Active Directory query tool, is commonly abused by threat actors such as Trickbot, Ryuk, Maze, and FIN6 for post-exploitation Active Directory reconnaissance, enabling enumeration of objects like computers, people, subnets, and domain information.

Active Directory Trickbot +3 adfind active-directory reconnaissance discovery windows
3r 5t
low advisory

Web Server Error Response Spike Indicating Reconnaissance

An unusual spike in web server error codes (500, 502, 503, 504) may indicate reconnaissance activities like vulnerability scanning or fuzzing, where attackers probe for weaknesses, potentially leading to exploitation of server-side issues.

Nginx +4 web-server reconnaissance vulnerability-scanning fuzzing
2r 2t
medium advisory

ESXi System Information Discovery via ESXCLI

Adversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.

ESXi reconnaissance vmware
2r 1t
low advisory

Rapid Enumeration of AWS S3 Buckets via API Calls

An AWS principal from a single source IP rapidly invokes read-only S3 control-plane APIs, revealing bucket posture across many buckets in a short time, potentially indicating automated reconnaissance or post-compromise enumeration.

Amazon S3 aws cloudtrail s3 reconnaissance
2r 4t
low advisory

Web Server Discovery or Fuzzing Activity Detection

This rule detects potential web server discovery or fuzzing activity by identifying a high volume of HTTP GET requests resulting in 404 or 403 status codes from a single source IP address within a short timeframe, indicating attackers discovering hidden resources for targeted attacks.

Nginx +4 web-server fuzzing reconnaissance web
2r 2t
medium advisory

Cisco ASA Device File Copy Activity

Adversaries may copy device files, including configurations and packet captures, from Cisco ASA devices via CLI or ASDM for reconnaissance, credential extraction, or data exfiltration, which can be detected via command execution logs.

Cisco ASA +1 cisco asa file_copy reconnaissance credential_access exfiltration
2r 2t
medium advisory

AWS IAM Access Denied Discovery Events

This detection identifies potential reconnaissance activity by an attacker attempting to discover AWS IAM permissions and configurations by generating a high volume of access denied events.

AWS IAM cloud aws iam reconnaissance
2r 1t
medium advisory

AzureHound Reconnaissance Activity in Azure AD

Detection of the AzureHound User-Agent in Azure AD logs indicates potential reconnaissance activity by adversaries mapping the Azure AD infrastructure for vulnerabilities.

Azure Active Directory +1 azuread reconnaissance azurehound
2r 2t
medium advisory

Windows EventLog Reconnaissance Activity Detection

This detection identifies potential reconnaissance activities on Windows systems by adversaries using tools like `wevtutil.exe`, `wmic.exe`, and PowerShell cmdlets to query event logs for sensitive information.

Windows eventlog reconnaissance
3r 1t
medium advisory

Suspicious WMI Reconnaissance via PowerShell

This analytic detects suspicious PowerShell activity leveraging WMI to gather system information, potentially indicating reconnaissance by an attacker.

Windows reconnaissance powershell wmi
2r 2t
medium advisory

Unsecured Elasticsearch Node Inbound Connection

This rule identifies potentially unsecured Elasticsearch nodes that lack TLS and/or authentication and are accepting inbound network connections, which could allow adversaries to gain initial access, exfiltrate data, or disrupt services.

Elasticsearch initial-access reconnaissance network
2r 2t
medium advisory

Kubernetes Multi-Resource Discovery Reconnaissance

Adversaries may perform reconnaissance in a Kubernetes environment by rapidly querying multiple resource types to map the environment and identify potential privilege escalation paths.

Kubernetes discovery reconnaissance
2r 1t
medium advisory

Windows Software Discovery via PowerShell Registry Queries

Attackers use PowerShell to query the Windows registry's Uninstall key to discover installed software and identify potential vulnerabilities for exploitation.

Splunk Enterprise +2 software-discovery powershell registry reconnaissance
2r 3t
low advisory

Web Server Reconnaissance via Unusual User Agents

Detection of unusual spikes in web server requests with uncommon or suspicious user-agent strings indicative of reconnaissance attempts to identify web application vulnerabilities or brute-force attacks.

Nginx +4 web-server reconnaissance vulnerability-scanning user-agent
2r 4t
medium advisory

Linux System Network Discovery via Multiple Utilities

Adversaries may attempt to enumerate local network configurations on Linux systems using common utilities like arp, ifconfig, ip, netstat, firewall-cmd, ufw, iptables, ss, and route to gather information for reconnaissance and subsequent attacks, leading to network mapping and vulnerability identification.

Linux network-discovery reconnaissance
2r 1t
medium advisory

Detection of Obfuscated IP Addresses via Command Line Tools

The use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.

Windows reconnaissance evasion command-line
3r 1t
medium advisory

Cisco ASA Reconnaissance Command Activity

This analytic detects potential reconnaissance on Cisco ASA devices by identifying execution of multiple information-gathering 'show' commands within a short timeframe, indicating potential enumeration by an attacker.

Cisco ASA cisco reconnaissance network
2r 3t
medium advisory

AWS Excessive Security Scanning Detection

Detection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.

AWS cloudtrail reconnaissance
2r 1t
low advisory

Active Directory Discovery via ADExplorer Execution

Detects the execution of ADExplorer, a tool used for Active Directory viewing and editing, which can be abused by adversaries for domain reconnaissance and creating offline snapshots of the AD database.

Microsoft Defender XDR +1 active-directory discovery reconnaissance windows
2r 5t
medium advisory

High Number of AWS Bedrock List Foundation Model Failures

Detection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.

Bedrock aws reconnaissance cloudtrail
2r 1t
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
low advisory

Web Server Discovery or Fuzzing Activity Detected

Detection of web server discovery or fuzzing activity indicated by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, suggesting attempts to discover hidden resources.

Nginx +4 web-server fuzzing reconnaissance web-application
2r 2t
low advisory

Web Server Discovery or Fuzzing Activity

Detection of potential web server discovery or fuzzing activity characterized by a high volume of HTTP GET requests resulting in 404 or 403 status codes originating from a single source IP address within a short timeframe, indicating attackers are probing for hidden resources.

Nginx +4 reconnaissance web-server fuzzing
2r 2t
medium advisory

Suspicious Enumeration Commands Spawned via WMIPrvSE

This rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.

Windows enumeration wmi reconnaissance
2r 13t
medium advisory

macOS DNS Request for IP Lookup Service via Unsigned Binary

An unsigned or untrusted binary on macOS is performing DNS requests for IP lookup services to determine the system's external IP address, which is commonly used by malware for reconnaissance before establishing C2 connections.

macOS discovery dns reconnaissance unsigned_binary
2r 1t 42i
medium advisory

Kubernetes Access Scanning Detection

This analytic detects potential reconnaissance activities within a Kubernetes environment by identifying repeated failed access attempts or unusual API requests from unauthenticated users based on Kubernetes audit logs, indicating a potential attacker's preliminary reconnaissance.

Kubernetes scanning reconnaissance
2r 1t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
low threat

AdFind Tool Used for Active Directory Reconnaissance

The execution of AdFind.exe, an Active Directory query tool, is often used by threat actors for post-exploitation Active Directory reconnaissance, as observed in campaigns involving Trickbot, Ryuk, Maze, and FIN6.

Elastic Defend FIN6 adfind active-directory reconnaissance windows
2r 5t