ATT&CKMatrixDiscovery

Discovery

TA0007

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to figure out your environment.

Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.

Techniques34

IDNameSub-techniquesExamples
T1007System Service Discovery069
T1010Application Window Discovery037
T1012Query Registry0119
T1016System Network Configuration Discovery2322
T1018Remote System Discovery0104
T1033System Owner/User Discovery0244
T1040Network Sniffing028
T1046Network Service Discovery073
T1049System Network Connections Discovery098
T1057Process Discovery0319
T1069Permission Groups Discovery388
T1082System Information Discovery0427
T1083File and Directory Discovery0373
T1087Account Discovery4158
T1120Peripheral Device Discovery058
T1124System Time Discovery0100
T1135Network Share Discovery077
T1201Password Policy Discovery08
T1217Browser Information Discovery029
T1482Domain Trust Discovery033
T1497Virtualization/Sandbox Evasion3153
T1518Software Discovery2195
T1526Cloud Service Discovery06
T1538Cloud Service Dashboard01
T1580Cloud Infrastructure Discovery06
T1613Container and Resource Discovery05
T1614System Location Discovery169
T1615Group Policy Discovery07
T1619Cloud Storage Object Discovery04
T1622Debugger Evasion026
T1652Device Driver Discovery04
T1654Log Enumeration010
T1673Virtual Machine Discovery05
T1680Local Storage Discovery0101

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.