Active Scanning: Wordlist Scanning T1595.003
Tactic: Reconnaissance
Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal is the identification of content and infrastructure rather than the discovery of valid credentials. Wordlists used in these scans may contain generic, commonly used names and file extensions or terms specific to a particular software. Adversaries may also create custom, target-specific wordlists using data gathered from other Reconnaissance techniques (ex: Gather Victim Org Information, or Search Victim-Owned Websites).
Authoring guide
These 9 rules share fields, values, and exclusions.
Fields filtered most (28 distinct)
These fields appear most often in rule filters.
Top indicator values (196 distinct)
These values appear most often in rule predicates.
Exclusions (18 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 9 rules
- GKE Anonymous Endpoint Permission Enumeration
- Kubernetes Potential Endpoint Permission Enumeration Attempt by Anonymous User Detected
- Potential Linux Hack Tool Launched
- Potential Spike in Web Server Error Logs
- Web Server Discovery or Fuzzing Activity
- Web Server Potential Command Injection Request
- Web Server Potential Spike in Error Response Codes
- Web Server Potential SQL Injection Request
- Web Server Suspicious User Agent Requests