Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.
Adversaries may search in different online sites depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: External Remote Services or Phishing).
Rules on DetectionCode tagged with T1593 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Suspicious Git Clone | medium | windows / process_creation | T1593.003 |
| Suspicious Git Clone - Linux | medium | linux / process_creation | T1593.003 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has gathered information on Colombian financial institutions, including Bancolombia, BBVA, Banco Caja Social, and Davivienda to craft phishing pages. |
| GroupContagious Interview | Contagious Interview has utilized open-source indicator of compromise repositories to determine their exposure to include VirusTotal, and MalTrail. |
| GroupMustang Panda | Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments. |
| GroupSandworm Team | Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails. |
| GroupStar Blizzard | Star Blizzard has used open-source research to identify information about victims to use in targeting. |
| GroupVolt Typhoon | Volt Typhoon has conducted pre-compromise web searches for victim information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.