Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Reconnaissance/ T1595

T1595Active Scanning

T1595 — Active Scanning is a MITRE ATT&CK technique in the Reconnaissance tactic. Clankerusecase tracks 8 detection use cases covering it and 1 threat-intel article citing it.

Reconnaissance
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
1Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (8)

Cisco SD-WAN Multiple Source IP vManage Admin SSH Authentication ESCU actions · hunting P Cisco SD-WAN Multiple SSH key Authentication from Same Source ESCU actions · hunting P Ollama Possible API Endpoint Scan Reconnaissance ESCU actions · hunting P Attacker Tools On Endpoint ESCU actions · alerting P Windows Netspy Network Scanner Execution ESCU actions · hunting P Cisco SA - Automated Web Reconnaissance via HTTP Access Errors ESCU actions · hunting P Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity ESCU actions · hunting P HTTP Rapid POST with Mixed Status Codes ESCU actions · hunting P

Articles citing this technique (1)