Techniques › T1592 › AN1958
AN1958 Analytic 1958
PRE · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Internet scanners may be used to look for patterns associated with malicious content designed to collect host information from visitors. Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.</p>
- Detects
- T1592 Gather Victim Host Information
- Part of
- DET0826 Detection of Gather Victim Host Information
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Internet Scan | None | DC0104 Response Content |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2013-0631 | Adobe ColdFusion | Mapped |
| CVE-2017-12637 | SAP NetWeaver | Mapped |