Discovery Detection Rules
The adversary is trying to figure out your environment. Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.
df00tech ships 68 production-ready detection rules mapped to the Discovery tactic (TA0007). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Discovery detections (68)
- CVE-2020-7796 Zimbra Collaboration Suite SSRF Exploitation (CVE-2020-7796)
- CVE-2021-22054 Omnissa Workspace ONE UEM Server-Side Request Forgery (CVE-2021-22054)
- CVE-2021-22175 GitLab SSRF Exploitation (CVE-2021-22175)
- CVE-2021-39935 GitLab SSRF via Import Feature (CVE-2021-39935)
- CVE-2024-57728 SimpleHelp Path Traversal Vulnerability (CVE-2024-57728)
- CVE-2025-31125 CVE-2025-31125: Vite Dev Server Improper Access Control
- CVE-2025-47813 Wing FTP Server Information Disclosure via Error Messages (CVE-2025-47813)
- CVE-2025-64446 CVE-2025-64446: Fortinet FortiWeb Path Traversal Exploitation
- CVE-2026-15409 SonicWall SMA1000 Server-Side Request Forgery Exploitation (CVE-2026-15409)
- CVE-2026-20133 Cisco Catalyst SD-WAN Manager Sensitive Information Exposure (CVE-2026-20133)
- CVE-2026-20230 Cisco Unified Communications Manager SSRF Exploitation Detected
- CVE-2026-20262 Cisco Catalyst SD-WAN Manager Path Traversal Exploitation
- CVE-2026-20805 Microsoft Windows Information Disclosure (CVE-2026-20805)
- CVE-2026-32966 Apache DolphinScheduler DataSource API Missing Authorization - Arbitrary Metadata Disclosure (CVE-2026-32966)
- CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Exploitation Attempt
- CVE-2026-42208 BerriAI LiteLLM SQL Injection Exploitation (CVE-2026-42208)
- CVE-2026-54350 Budibase Anonymous NoSQL Operator Injection via Published-App Query Templates
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- T1007 System Service Discovery
- T1010 Application Window Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1016.002 Wi-Fi Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1040 Network Sniffing
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1069 Permission Groups Discovery
- T1069.001 Local Groups
- T1069.002 Domain Groups
- T1069.003 Cloud Groups
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1087.003 Email Account
- T1087.004 Cloud Account
- T1120 Peripheral Device Discovery
- T1124 System Time Discovery
- T1135 Network Share Discovery
- T1201 Password Policy Discovery
- T1217 Browser Information Discovery
- T1482 Domain Trust Discovery
- T1497 Virtualization/Sandbox Evasion
- T1497.001 System Checks
- T1497.002 User Activity Based Checks
- T1497.003 Time Based Checks
- T1518 Software Discovery
- T1518.001 Security Software Discovery
- T1518.002 Backup Software Discovery
- T1526 Cloud Service Discovery
- T1538 Cloud Service Dashboard
- T1580 Cloud Infrastructure Discovery
- T1613 Container and Resource Discovery
- T1614 System Location Discovery
- T1614.001 System Language Discovery
- T1615 Group Policy Discovery
- T1619 Cloud Storage Object Discovery
- T1622 Debugger Evasion
- T1652 Device Driver Discovery
- T1654 Log Enumeration
- T1673 Virtual Machine Discovery
- T1680 Local Storage Discovery
- THREAT-Ransomware-StagingIndicators Ransomware Pre-Deployment Staging Indicators
Related tactics
266 detections
225 detections