Compliance Node Overview
MITRE ATT&CK T1596.005 (Scan Databases) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search within public scan databases for information about victims that can be used during targeting. Various online services continuously publish the results of Internet scans/surveys, often harvesting information such as active IP addresses, hostnames, open ports, certificates, and even server banners. Adversaries may search scan databases to gather actionable information. Threat actors can use online resources and lookup tools to harvest information from these services. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1596/005/
SHA-256 integrity: 378e953ba37074506e36f5d8a745d2aa15994a89ecf05ac33a47d3f38d12a204
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1596.005: Scan Databases (https://attack.mitre.org/techniques/T1596/005/)
- MITRE ATT&CK Tactic TA0043: Reconnaissance (https://attack.mitre.org/tactics/TA0043/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.