Gather Victim Network Information

T1590

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP ranges, domain names, etc.) as well as specifics regarding its topology and operations.

Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Information about networks may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Active Scanning or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: Trusted Relationship).

Detection rules12

Rules on DetectionCode tagged with T1590 or one of its sub-techniques.

Sigma4

RuleLevelLog sourceTechnique
PUA - Crassus Executionhighwindows / process_creationT1590.001
Failed DNS Zone Transfermediumwindows / NULLT1590.002
PUA - Advanced IP/Port Scanner Update CheckmediumNULL / proxyT1590
Suspicious DNS Query for IP Lookup Service APIsmediumwindows / dns_queryT1590

Splunk8

RuleTypeRiskData sourceTechnique
Cisco ASA - Reconnaissance Command ActivityAnomalyNULLCisco ASA LogsT1590.001 T1590.005
Cisco IOS XE Reconnaissance Command ActivityAnomalyNULLCisco IOS LogsT1590
Cisco NVM - Suspicious Network Connection to IP Lookup Service APIAnomalyNULLCisco Network Visibility Module Flow DataT1590.005
Local LLM Framework DNS QueryHuntingNULLSysmon EventID 22T1590
Wermgr Process Connecting To IP Check Web ServicesTTPNULLSysmon EventID 22T1590.005
Windows DNS Gather Network InfoAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1590.002
Windows Gather Victim Network Info Through Ip Check Web ServicesAnomalyNULLSysmon EventID 22T1590.005
Windows WinPEAS PowerShell Script ExecutionTTPNULLPowershell Script Block Logging 4104T1590

Sub-techniques6

IDNameExamples
T1590.001Domain Properties2
T1590.002DNS0
T1590.003Network Trust Dependencies0
T1590.004Network Topology5
T1590.005IP Addresses3
T1590.006Network Security Appliances2

Groups3

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

Groups3

Used byProcedure example
GroupHAFNIUM

HAFNIUM gathered the fully qualified domain names (FQDNs) for targeted Exchange servers in the victim's environment.

GroupIndrik Spider

Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.

GroupVolt Typhoon

Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.

References3

  1. Circl Passive DNS Open source
    CIRCL Computer Incident Response Center. (n.d.). Passive DNS. Retrieved October 20, 2020.
  2. DNS Dumpster Open source
    Hacker Target. (n.d.). DNS Dumpster. Retrieved October 20, 2020.
  3. WHOIS Open source
    NTT America. (n.d.). Whois Lookup. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.