TA0007

Discovery Detection Rules

The adversary is trying to figure out your environment. Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.

df00tech ships 68 production-ready detection rules mapped to the Discovery tactic (TA0007). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.

Unlock the full Pro package

Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.

Upgrade to Pro

Discovery detections (68)

Related tactics

All MITRE ATT&CK Tactics