Reconnaissance Detection Rules
The adversary is trying to gather information they can use to plan future operations. Reconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to plan and execute Initial Access, to scope and prioritize post-compromise objectives, or to drive and lead further Reconnaissance efforts.
df00tech ships 45 production-ready detection rules mapped to the Reconnaissance tactic (TA0043). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Reconnaissance detections (45)
- T1589 Gather Victim Identity Information
- T1589.001 Credentials
- T1589.002 Email Addresses
- T1589.003 Employee Names
- T1590 Gather Victim Network Information
- T1590.001 Domain Properties
- T1590.002 DNS
- T1590.003 Network Trust Dependencies
- T1590.004 Network Topology
- T1590.005 IP Addresses
- T1590.006 Network Security Appliances
- T1591 Gather Victim Org Information
- T1591.001 Determine Physical Locations
- T1591.002 Business Relationships
- T1591.003 Identify Business Tempo
- T1591.004 Identify Roles
- T1592 Gather Victim Host Information
- T1592.001 Hardware
- T1592.002 Software
- T1592.003 Firmware
- T1592.004 Client Configurations
- T1593 Search Open Websites/Domains
- T1593.001 Social Media
- T1593.002 Search Engines
- T1593.003 Code Repositories
- T1594 Search Victim-Owned Websites
- T1595 Active Scanning
- T1595.001 Scanning IP Blocks
- T1595.002 Vulnerability Scanning
- T1595.003 Wordlist Scanning
- T1596 Search Open Technical Databases
- T1596.001 DNS/Passive DNS
- T1596.002 WHOIS
- T1596.003 Digital Certificates
- T1596.004 CDNs
- T1596.005 Scan Databases
- T1597 Search Closed Sources
- T1597.001 Threat Intel Vendors
- T1597.002 Purchase Technical Data
- T1598 Phishing for Information
- T1598.001 Spearphishing Service
- T1598.002 Spearphishing Attachment
- T1598.003 Spearphishing Link
- T1598.004 Spearphishing Voice
- T1681 Search Threat Vendor Data