Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1046

T1046Network Service Discovery

T1046 — Network Service Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 20 detection use cases covering it and 10 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
20Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (20)

Cisco IOS XE Remote Access Probe Burst ESCU actions · hunting P Kubernetes Access Scanning ESCU actions · hunting P Kubernetes Scanning by Unauthenticated IP Address ESCU actions · hunting P Advanced IP or Port Scanner Execution ESCU actions · hunting P Windows PsTools Recon Usage ESCU actions · hunting P Cisco Secure Firewall - Blocked Connection ESCU actions · hunting P Cisco Secure Firewall - Repeated Blocked Connections ESCU actions · hunting P Internal Horizontal Port Scan ESCU actions · alerting P Internal Horizontal Port Scan NMAP Top 20 ESCU actions · alerting P Internal Vertical Port Scan ESCU actions · alerting P Internal Vulnerability Scan ESCU actions · alerting P [LLM] Evooo1Bot SSH brute-force scanner — outbound port-22 fan-out from a single host Bespoke actions · hunting DSPCS [LLM] FSCAN internal network reconnaissance fan-out Bespoke actions · hunting DSΣPDDCS [LLM] Autonomous mass-scan burst: langflow_poc.py multi-threaded FOFA target sweep Bespoke recon · alerting DSΣPDDCS [LLM] Fluentd RCE pod fans out to internal cluster ranges (post-exploitation lateral movement) Bespoke actions · alerting DSPDDCS [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] goshs launched with vulnerable --no-delete + WebDAV config (CVE-2026-64863) Bespoke recon · alerting DSΣPDDCS [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] TuxBot Telnet/ADB scanner fan-out (credential brute-force propagation) Bespoke delivery · alerting DSPCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS

Articles citing this technique (10)