kevmap

TechniquesT1595.003 › AN2000

AN2000 Analytic 2000

PRE · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet).</p>
Detects
T1595.003 Wordlist Scanning
Part of
DET0868 Detection of Wordlist Scanning

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
Network TrafficNoneDC0085 Network Traffic Content