MITRE ATT&CK technique
Gather Victim Network Information detection rulesT1590
Gather Victim Network Information (T1590) is a MITRE ATT&CK technique in the Reconnaissance tactic. This page lists the 4 community-maintained Sigma detection rules in the library mapped to T1590 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1590 on attack.mitre.org4 rules
Top products
Tactic
PUA - Crassus Execution
highDetects Crassus, a Windows privilege escalation discovery tool, based on PE metadata characteristics.
windows · process_creation
Failed DNS Zone Transfer
mediumDetects when a DNS zone transfer failed.
windows
PUA - Advanced IP/Port Scanner Update Check
mediumDetect the update check performed by Advanced IP/Port Scanner utilities.
proxy
Suspicious DNS Query for IP Lookup Service APIs
mediumDetects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.
windows · dns_query