What MITRE ATT&CK T1046: Network Service Discovery (Enterprise Tactic TA0007 - Discovery) requires
MITRE ATT&CK T1046 (Network Service Discovery) is an Enterprise Discovery technique. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port and/or vulnerability scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Affected platforms: Windows, IaaS, Linux, macOS, Containers, Network. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1031 Network Intrusion Prevention, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, CM-02, CM-06, CM-07, CM-08, RA-05, SC-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1046/
SHA-256 integrity: 29d7d7012b94f13d22e8b9a403c042b98506acf6aff35737738e411a98035156
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1046: Network Service Discovery (https://attack.mitre.org/techniques/T1046/)
- MITRE ATT&CK Tactic TA0007: Discovery (https://attack.mitre.org/tactics/TA0007/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access