Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1046

T1046Network Service Discovery

T1046 — Network Service Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 21 detection use cases covering it and 11 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
21Use cases
11Articles
0Sub-techniques
1Tactic

Use cases covering this technique (21)

Cisco IOS XE Remote Access Probe Burst ESCU actions · hunting P Kubernetes Access Scanning ESCU actions · hunting P Kubernetes Scanning by Unauthenticated IP Address ESCU actions · hunting P Advanced IP or Port Scanner Execution ESCU actions · hunting P Windows PsTools Recon Usage ESCU actions · hunting P Cisco Secure Firewall - Blocked Connection ESCU actions · hunting P Cisco Secure Firewall - Repeated Blocked Connections ESCU actions · hunting P Internal Horizontal Port Scan ESCU actions · alerting P Internal Horizontal Port Scan NMAP Top 20 ESCU actions · alerting P Internal Vertical Port Scan ESCU actions · alerting P Internal Vulnerability Scan ESCU actions · alerting P [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] Inbound network access to Ruflo bridge (3001) / MongoDB (27017) from public source Bespoke delivery · hunting DSPDDCSCW [LLM] IPMI/BMC service discovery scan across many hosts (UDP/623) Bespoke recon · alerting DSPDDCSCW [LLM] Inbound DHCPv6 to odhcpd (UDP 547) from non-link-local source — CVE-2026-53921 exploit reach Bespoke delivery · hunting SP [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] TuxBot Telnet/ADB scanner fan-out (credential brute-force propagation) Bespoke delivery · alerting DSPCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS [LLM] The Gentlemen internal reconnaissance via Advanced IP Scanner Bespoke recon · hunting DSΣPDDCS [LLM] Recon scanning of 9router unauthenticated /api/* endpoints from single source Bespoke recon · hunting SP [LLM] Apache Camel DNS SSRF egress: app server (java) resolving via external / attacker DNS resolver Bespoke actions · hunting DSΣPDDCS

Articles citing this technique (11)