T1590 Gather Victim Network Information
Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP ranges, domain names, etc.) as well as specifics regarding its topology and operations. Adversaries may gather this information in various ways, such as direct collection actions via [Active…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- PUA - Crassus Executionhightest · windows
- Failed DNS Zone Transfermediumtest · windows
- PUA - Advanced IP/Port Scanner Update Checkmediumtest · proxy
- Suspicious DNS Query for IP Lookup Service APIsmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.