FORENSIA

ATT&CK · T1046

Network Service Discovery

Tactics: discovery

About

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well. Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as <code>dns-sd -B _ssh._tcp .</code>) to find other systems broadcasting the ssh service.

Platforms: Containers, IaaS, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

31 known groups

Software

35 malware/tools implement this

China ChopperHDoorBlackEnergyBackdoor.OldreaXTunnelRemsecCobalt StrikePupyMURKYTOPKoadicInvisiMoleXbashEmpireSpeakUpPoshC2ZxShellRamsayLuciferCaterpillar WebShellPysaNBTscanP.A.S. WebshellHildegardIndustroyerConfickerPeiratesSILENTTRINITYHermeticWizardBrute Ratel C4RoyalBADHATCHFRPMgBotBlackByte RansomwareLightSpy

Corpus indicators tagged with this technique

198 indicators in the corpus carry T1046.

IndicatorTypeFamilySevSrc
cve-2025-34054cve854
cve-2025-11837cve852
cve-2016-5681cve852
cve-2021-27137cve858
cve-2016-15047cve854
cve-2013-3307cve852
cve-2016-0638cvephishing851
cve-2022-47945cve851
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
6869f24aecd75e2144aba8dc03dc2d0fhash802
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
a3e3197e2344c51e95c063541ea22205hash802
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
0a2d2a4ec1ca2aa6a23a35abb5a75451hash802
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
05627d1bddb7292bb45139244f46051fhash802
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
0ffb4b4e430f4b69216fb9d2e082e482hash802
19232d0eff3ef7aee3b5d7620c72358chash802
36ff9f683e870145aaf5a715bc934762hash802
8cc249b16adf7e4a658af7fa31d7998ehash802
6f761f63642cd6329a29cfad80be50c3hash802
6f91d1f8f0cbaab137351936b52f7a94hash802
7461445fca3f9d8911148e0908d33c3bhash802
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
dc35086ba0f5f83545c32a023a1f3be4hash802
ea2fe3b409da439aec25cf7eabf5b7a7hash802
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801

Showing the top 30 by severity of 198.