Detect Gather Victim Network Information in Microsoft Sentinel
This detection identifies adversary reconnaissance activity targeting victim network information, including IP ranges, domain names, DNS records, network topology, and security appliance configurations. Because T1590 is a PRE-ATT&CK technique, direct detection within the victim environment is limited; however, second-order indicators are observable when adversaries deploy internal network enumeration tools post-compromise (as seen with Volt Typhoon, Indrik Spider, and HAFNIUM), attempt DNS zone transfers, execute WHOIS or DNS enumeration utilities, or run network discovery tools such as Lansweeper and Advanced IP Scanner. Detection focuses on process execution of known network reconnaissance binaries, DNS zone transfer attempts, and anomalous internal network topology queries that suggest an adversary mapping the environment for lateral movement or targeting.
MITRE ATT&CK
- Tactic
- Reconnaissance
- Technique
- T1590 Gather Victim Network Information
- Canonical reference
- https://attack.mitre.org/techniques/T1590/
KQL Detection Query
let NetworkReconTools = dynamic(["nmap", "masscan", "zmap", "lansweeper", "angryip", "fping", "nbtscan", "netdiscover", "unicornscan", "dnsenum", "dnsrecon", "fierce", "sublist3r", "amass", "theharvester", "advanced_port_scanner", "advanced ip scanner"]);
let DnsReconPatterns = dynamic(["axfr", "AXFR", "zone-transfer", "zone transfer", "-t ANY", "ls -d"]);
let NetworkCmdRecon = dynamic(["ipconfig /all", "nslookup", "arp -a", "netstat -ano", "route print", "net view", "nltest /dclist", "nltest /domain_trusts"]);
DeviceProcessEvents
| where TimeGenerated > ago(1d)
| where (
FileName has_any (NetworkReconTools)
or ProcessVersionInfoOriginalFileName has_any (NetworkReconTools)
or ProcessCommandLine has_any (NetworkReconTools)
or ProcessCommandLine has_any (DnsReconPatterns)
or (FileName in~ ("nslookup.exe", "dig.exe", "host.exe") and ProcessCommandLine has_any (DnsReconPatterns))
or (FileName in~ ("nltest.exe") and ProcessCommandLine has_any ("/dclist", "/domain_trusts", "/trusted_domains", "/dsgetdc"))
)
| extend ReconCategory = case(
ProcessCommandLine has_any ("nmap", "masscan", "zmap", "fping", "nbtscan"), "PortHostScanning",
ProcessCommandLine has_any ("dnsenum", "dnsrecon", "fierce", "axfr", "AXFR", "zone-transfer"), "DNSEnumeration",
ProcessCommandLine has_any ("lansweeper", "advanced_port_scanner", "angryip", "netdiscover"), "NetworkDiscoveryTool",
ProcessCommandLine has_any ("/dclist", "/domain_trusts", "/trusted_domains"), "DomainTrustEnumeration",
"GeneralNetworkRecon")
| extend SuspicionScore = case(
ReconCategory == "PortHostScanning", 90,
ReconCategory == "DNSEnumeration", 85,
ReconCategory == "NetworkDiscoveryTool", 80,
ReconCategory == "DomainTrustEnumeration", 70,
50)
| project TimeGenerated, DeviceName, AccountDomain, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, ReconCategory, SuspicionScore
| order by SuspicionScore desc, TimeGenerated desc Detects execution of known network reconnaissance binaries (nmap, masscan, Lansweeper, dnsrecon, fierce, etc.), DNS zone transfer attempts via nslookup/dig with AXFR queries, and domain trust enumeration via nltest. Scores findings by category to prioritize active port scanners and DNS enumeration over lower-confidence signals.
Data Sources
Required Tables
False Positives & Tuning
- Legitimate network administrators running nmap or Advanced IP Scanner for asset inventory or troubleshooting
- IT operations teams using Lansweeper or similar tools for scheduled network discovery and CMDB updates
- DNS administrators performing authoritative zone transfers between primaries and secondaries as part of normal operations
- Security teams running authorized vulnerability scans or penetration tests using tools like nmap or masscan
- nltest calls from legitimate domain join operations, group policy processing, or identity management tools
Other platforms for T1590
Testing Methodology
Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Nmap Internal Subnet Port Scan
Expected signal: Sysmon EventCode 1 (process create) with Image=nmap.exe, CommandLine containing the subnet range. Sysmon EventCode 3 (network connect) showing connections from nmap.exe to multiple internal IPs on specified ports. DeviceProcessEvents and DeviceNetworkEvents telemetry in MDE.
- Test 2DNS Zone Transfer Attempt via nslookup
Expected signal: Sysmon EventCode 1 with Image=nslookup.exe, CommandLine containing 'AXFR' and the target domain. Windows DNS debug log (if enabled) will show an AXFR request from the client IP. DeviceProcessEvents in MDE captures the command line.
- Test 3Domain Trust Enumeration via nltest
Expected signal: Sysmon EventCode 1 (process create) for each nltest invocation with the respective flags in CommandLine. SecurityEvent EventID 4688 if process command line auditing is enabled via GPO. DeviceProcessEvents in MDE with full command line captured.
- Test 4Internal Network Discovery with Advanced IP Scanner
Expected signal: DeviceFileEvents showing advanced_ip_scanner.exe created in C:\Temp. Sysmon EventCode 11 (file create) for the binary. Process creation event for advanced_ip_scanner.exe. Network connection events to multiple internal IPs during scan. DeviceNetworkEvents in MDE showing mass internal connections.
References (5)
- https://attack.mitre.org/techniques/T1590/
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
- https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- https://www.secureworks.com/research/indrik-spider
Unlock Pro Content
Get the full detection package for T1590 including response playbook, investigation guide, and atomic red team tests.