MITRE ATT&CK technique
Network Service Discovery detection rulesT1046
Network Service Discovery (T1046) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 20 community-maintained Sigma detection rules in the library mapped to T1046 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, opencanary, linux.
Top products
Tactic
Grixba Malware Reconnaissance Activity
highDetects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
windows · process_creation
HackTool - winPEAS Execution
highWinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
windows · process_creation
HackTool - WinPwn Execution
highDetects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
windows · process_creation
HackTool - WinPwn Execution - ScriptBlock
highDetects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
windows · ps_script
OpenCanary - Host Port Scan (SYN Scan)
highDetects instances where an OpenCanary node has been targeted by a SYN port scan.
opencanary · application
OpenCanary - NMAP FIN Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP FIN Scan
opencanary · application
OpenCanary - NMAP NULL Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP NULL Scan
opencanary · application
OpenCanary - NMAP OS Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP OS Scan
opencanary · application
OpenCanary - NMAP XMAS Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP XMAS Scan
opencanary · application
Advanced IP Scanner - File Event
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · file_event
Pnscan Binary Data Transmission Activity
mediumDetects command line patterns associated with the use of Pnscan for sending and receiving binary data across the network. This behavior has been identified in a Linux malware campaign targeting Docker, Apache Hadoop, Redis, and Confluence and was previously used by the threat actor known as TeamTNT
linux · process_creation
PUA - Advanced IP Scanner Execution
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · process_creation
PUA - Advanced Port Scanner Execution
mediumDetects the use of Advanced Port Scanner.
windows · process_creation
PUA - NimScan Execution
mediumDetects usage of NimScan, a portscanner utility. In early 2025, adversaries were observed using this utility to scan for open ports on remote hosts in a compromised environment. This rule identifies the execution of NimScan based on the process image name and specific hash values associated with different versions of the tool.
windows · process_creation
PUA - Nmap/Zenmap Execution
mediumDetects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation
windows · process_creation
PUA - SoftPerfect Netscan Execution
mediumDetects usage of SoftPerfect's "netscan.exe". An application for scanning networks. It is actively used in-the-wild by threat actors to inspect and understand the network architecture of a victim.
windows · process_creation
Python Initiated Connection
mediumDetects a Python process initiating a network connection. While this often relates to package installation, it can also indicate a potential malicious script communicating with a C&C server.
windows · network_connection
Linux Network Service Scanning - Auditd
lowDetects enumeration of local or remote network services.
linux
Linux Network Service Scanning Tools Execution
lowDetects execution of network scanning and reconnaisance tools. These tools can be used for the enumeration of local or remote network services for example.
linux · process_creation
MacOS Network Service Scanning
lowDetects enumeration of local or remote network services.
macos · process_creation