What MITRE ATT&CK T1018: Remote System Discovery (Enterprise Tactic TA0007 - Discovery) requires
MITRE ATT&CK T1018 describes adversary enumeration of remote systems on the network to enable lateral movement planning. Tools include built-in net commands, nltest, BloodHound, SharpHound, and PowerView. Active Directory enumeration is a hallmark of ransomware operators and APT groups. Compliance obligations include network segmentation (NIST 800-53 SC-7, PCI DSS Req 1.4), Active Directory hardening (Microsoft Security Compass tier model), and behavioural detection of enumeration tooling under ISO 27001 A.8.16 and NIS2 Article 21.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1018/
SHA-256 integrity: 3022514b12b4a6ef965b229d04d2b828b153e86e94f09c3cb91621572e8c9714
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1018: Remote System Discovery (https://attack.mitre.org/techniques/T1018/)
- NIST SP 800-53 Rev 5: SC-7 (Boundary Protection), AC-4 (Information Flow Enforcement)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1018-remote-system-discovery.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1018-remote-system-discovery.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1018-remote-system-discovery
- Back to registry: Browse all 10,085 compliance nodes