Network Service Discovery, Technique T1046 - Enterprise (original) (raw)

C0063

2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.[4]

G1030

Agrius

Agrius used the open-source port scanner WinEggDrop to perform detailed scans of hosts of interest in victim networks.[5]

C0062

Anthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to enumerate internal network services and endpoints across targeted environments using browser automation via MCP, including databases, container registries, admin interfaces, and workflow orchestration platforms.[6]

G0050

APT32

APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities.[7]

G0087

APT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.[8][9]

G0096

APT41

APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets.[10]

S0093

Backdoor.Oldrea

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.[11]

G0135

BackdoorDiplomacy

BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware.[12]

S1081

BADHATCH

BADHATCH can check for open ports on a computer by establishing a TCP connection.[13]

G1043

BlackByte

BlackByte has used tools such as NetScan to enumerate network services in victim environments.[14]

S1180

BlackByte Ransomware

BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads.[15]

S0089

BlackEnergy

BlackEnergy has conducted port scans on a host.[16]

G0098

BlackTech

BlackTech has used the SNScan tool to find other potential targets on victim networks.[17]

S1063

Brute Ratel C4

Brute Ratel C4 can conduct port scanning against targeted systems.[18]

C0018

C0018

During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning.[19]

C0027

C0027

During C0027, used RustScan to scan for open ports on targeted ESXi appliances.[20]

S0572

Caterpillar WebShell

Caterpillar WebShell has a module to use a port scanner on a system.[21]

G0114

Chimera

Chimera has used the get -b -e -p command for network scanning as well as a custom Python tool packed into a Windows executable named Get.exe to scan IP ranges for HTTP.[22]

S0020

China Chopper

China Chopper's server component can spider authentication portals.[23]

G0080

Cobalt Group

Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning.[24][25][26]

S0154

Cobalt Strike

Cobalt Strike can perform port scans from an infected host.[27][28][29]

S0608

Conficker

Conficker scans for other machines to infect.[30]

C0004

CostaRicto

During CostaRicto, the threat actors employed nmap and pscan to scan target environments.[31]

G0105

DarkVishnya

DarkVishnya performed port scanning to obtain the list of active services.[32]

G1003

Ember Bear

Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments.[33]

S0363

Empire

Empire can perform port scans from an infected host.[34]

G1016

FIN13

FIN13 has utilized nmap for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.[35][36]

G0037

FIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.[37]

G0117

Fox Kitten

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.[38][39]

S1144

FRP

As part of load balancing FRP can set healthCheck.type = "tcp" or healthCheck.type = "http" to check service status on specific hosts with TCPing or an HTTP request.[40]

S0061

HDoor

HDoor scans to identify open ports on the victim.[41]

S0698

HermeticWizard

HermeticWizard has the ability to scan ports on a compromised network.[42]

S0601

Hildegard

Hildegard has used masscan to look for kubelets in the internal Kubernetes network.[43]

C0038

HomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.[44][45]

G1032

INC Ransom

INC Ransom has used NETSCAN.EXE for internal reconnaissance.[46][47]

S0604

Industroyer

Industroyer uses a custom port scanner to map out a network.[48]

S0260

InvisiMole

InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols.[49]

S0250

Koadic

Koadic can scan for open TCP ports on the target network.[50]

G0032

Lazarus Group

Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network.[51]

G0077

Leafminer

Leafminer scanned network services to search for vulnerabilities in the victim system.[52]

S1185

LightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the /Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist file.It also utilizes Apple's CWWiFiClient API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.[53]

G0030

Lotus Blossom

Lotus Blossom has used port scanners to enumerate services on remote hosts.[54]

S0532

Lucifer

Lucifer can scan for open ports including TCP ports 135 and 1433.[55]

G0059

Magic Hound

Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning.[56]

G1051

Medusa Group

Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.[57] Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (netscan.exe) to discover device hostnames and network services.[58]

G0045

menuPass

menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest.[59]

S1146

MgBot

MgBot includes modules for performing HTTP and server service scans.[60]

S0233

MURKYTOP

MURKYTOP has the capability to scan for open ports on hosts in a connected network.[23]

G0129

Mustang Panda

Mustang Panda has leveraged NBTscan to scan IP networks.[61]

G0019

Naikon

Naikon has used the LadonGo scanner to scan target networks.[62]

S0590

NBTscan

NBTscan can be used to scan IP networks.[63][64]

G0049

OilRig

OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning.[65]

C0014

Operation Wocao

During Operation Wocao, threat actors scanned for open ports and used nbtscan to find NETBIOS nameservers.[66]

S0598

P.A.S. Webshell

P.A.S. Webshell can scan networks for open ports and listening services.[67]

S0683

Peirates

Peirates can initiate a port scan against a given IP address.[68]

S0378

PoshC2

PoshC2 can perform port scans from an infected host.[69]

S0192

Pupy

Pupy has a built-in module for port scanning.[70]

S0583

Pysa

Pysa can perform network reconnaissance using the Advanced Port Scanner tool.[71]

S0458

Ramsay

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.[72][73]

G1039

RedCurl

RedCurl has used netstat to check if port 4119 is open.[74]

S0125

Remsec

Remsec has a plugin that can perform ARP scanning as well as port scanning.[75]

G0106

Rocke

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.[76][77]

S1073

Royal

Royal can scan the network interfaces of targeted systems.[78]

S0692

SILENTTRINITY

SILENTTRINITY can scan for open ports on a compromised machine.[79]

S0374

SpeakUp

SpeakUp checks for availability of specific ports on servers.[80]

G0039

Suckfly

Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open.[81]

G0139

TeamTNT

TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters.[82][43][83] TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments.[84]

G0027

Threat Group-3390

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.[85][86]

G0081

Tropic Trooper

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.[87][88]

G1017

Volt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.[89]

S0341

Xbash

Xbash can perform port scanning of TCP and UDP ports.[90]

S0117

XTunnel

XTunnel is capable of probing the network for open ports.[91]

S0412

ZxShell

ZxShell can launch port scans.[10][92]