Tactic.View on attack.mitre.org
The adversary is trying to figure out your environment.
Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1007 | System Service Discovery | 0 | 69 |
| T1010 | Application Window Discovery | 0 | 37 |
| T1012 | Query Registry | 0 | 119 |
| T1016 | System Network Configuration Discovery | 2 | 322 |
| T1018 | Remote System Discovery | 0 | 104 |
| T1033 | System Owner/User Discovery | 0 | 244 |
| T1040 | Network Sniffing | 0 | 28 |
| T1046 | Network Service Discovery | 0 | 73 |
| T1049 | System Network Connections Discovery | 0 | 98 |
| T1057 | Process Discovery | 0 | 319 |
| T1069 | Permission Groups Discovery | 3 | 88 |
| T1082 | System Information Discovery | 0 | 427 |
| T1083 | File and Directory Discovery | 0 | 373 |
| T1087 | Account Discovery | 4 | 158 |
| T1120 | Peripheral Device Discovery | 0 | 58 |
| T1124 | System Time Discovery | 0 | 100 |
| T1135 | Network Share Discovery | 0 | 77 |
| T1201 | Password Policy Discovery | 0 | 8 |
| T1217 | Browser Information Discovery | 0 | 29 |
| T1482 | Domain Trust Discovery | 0 | 33 |
| T1497 | Virtualization/Sandbox Evasion | 3 | 153 |
| T1518 | Software Discovery | 2 | 195 |
| T1526 | Cloud Service Discovery | 0 | 6 |
| T1538 | Cloud Service Dashboard | 0 | 1 |
| T1580 | Cloud Infrastructure Discovery | 0 | 6 |
| T1613 | Container and Resource Discovery | 0 | 5 |
| T1614 | System Location Discovery | 1 | 69 |
| T1615 | Group Policy Discovery | 0 | 7 |
| T1619 | Cloud Storage Object Discovery | 0 | 4 |
| T1622 | Debugger Evasion | 0 | 26 |
| T1652 | Device Driver Discovery | 0 | 4 |
| T1654 | Log Enumeration | 0 | 10 |
| T1673 | Virtual Machine Discovery | 0 | 5 |
| T1680 | Local Storage Discovery | 0 | 101 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.