MITRE ATT&CK technique
Active Scanning detection rulesT1595
Active Scanning (T1595) is a MITRE ATT&CK technique in the Reconnaissance tactic. This page lists the 5 community-maintained Sigma detection rules in the library mapped to T1595 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Top products
Tactic
DNS Query to External Service Interaction Domains
highDetects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent.
dns
Grixba Malware Reconnaissance Activity
highDetects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
windows · process_creation
PUA - PingCastle Execution From Potentially Suspicious Parent
highDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
windows · process_creation
Potential Hello-World Scraper Botnet Activity
mediumDetects network traffic potentially associated with a scraper botnet variant that uses the "Hello-World/1.0" user-agent string.
proxy
PUA - PingCastle Execution
mediumDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level.
windows · process_creation