Reconnaissance Detection Rules
The adversary is trying to gather information they can use to plan future operations. Reconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to plan and execute Initial Access, to scope and prioritize post-compromise objectives, or to drive and lead further Reconnaissance efforts.
df00tech ships 69 production-ready detection rules mapped to the Reconnaissance tactic (TA0043). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Reconnaissance detections (69)
- CVE-2020-7796 Zimbra Collaboration Suite SSRF Exploitation (CVE-2020-7796)
- CVE-2021-22054 Omnissa Workspace ONE UEM Server-Side Request Forgery (CVE-2021-22054)
- CVE-2021-22175 GitLab SSRF Exploitation (CVE-2021-22175)
- CVE-2021-39935 GitLab SSRF via Import Feature (CVE-2021-39935)
- CVE-2025-47813 Wing FTP Server Information Disclosure via Error Messages (CVE-2025-47813)
- CVE-2025-68686 Fortinet FortiOS Sensitive Information Exposure (CVE-2025-68686)
- CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read (CVE-2026-3055)
- CVE-2026-20230 Cisco Unified Communications Manager SSRF Exploitation Detected
- CVE-2026-45321 TanStack Router Unspecified Vulnerability Exploitation
- CVE-2026-53513 CVE-2026-53513: @better-auth/sso Provider Registration SSRF via Unvalidated OIDC Endpoints
- T1589 Gather Victim Identity Information
- T1589.001 Credentials
- T1589.002 Email Addresses
- T1589.003 Employee Names
- T1590 Gather Victim Network Information
- T1590.001 Domain Properties
- T1590.002 DNS
- T1590.003 Network Trust Dependencies
- T1590.004 Network Topology
- T1590.005 IP Addresses
- T1590.006 Network Security Appliances
- T1591 Gather Victim Org Information
- T1591.001 Determine Physical Locations
- T1591.002 Business Relationships
- T1591.003 Identify Business Tempo
- T1591.004 Identify Roles
- T1592 Gather Victim Host Information
- T1592.001 Hardware
- T1592.002 Software
- T1592.003 Firmware
- T1592.004 Client Configurations
- T1593 Search Open Websites/Domains
- T1593.001 Social Media
- T1593.002 Search Engines
- T1593.003 Code Repositories
- T1594 Search Victim-Owned Websites
- T1595 Active Scanning
- T1595.001 Scanning IP Blocks
- T1595.002 Vulnerability Scanning
- T1595.003 Wordlist Scanning
- T1596 Search Open Technical Databases
- T1596.001 DNS/Passive DNS
- T1596.002 WHOIS
- T1596.003 Digital Certificates
- T1596.004 CDNs
- T1596.005 Scan Databases
- T1597 Search Closed Sources
- T1597.001 Threat Intel Vendors
- T1597.002 Purchase Technical Data
- T1598 Phishing for Information
- T1598.001 Spearphishing Service
- T1598.002 Spearphishing Attachment
- T1598.003 Spearphishing Link
- T1598.004 Spearphishing Voice
- T1681 Search Threat Vendor Data
- THREAT-Recon-AICrawlerRobotsExclusionAbuse AI/LLM Crawler Bot Robots.txt Exclusion Violation and User-Agent Spoofing
- THREAT-Recon-AttachmentForcedSMBAuthNTLMHarvest Email Attachment Forces Outbound SMB Authentication to Harvest NTLM Hashes
- THREAT-Recon-AutomatedVulnScannerSweep Automated Vulnerability Scanner Sweep Against External Attack Surface
- THREAT-Recon-CloudAssetShadowITDiscovery Cloud Asset & Shadow IT Discovery via Internet-Wide Scanning Services
- THREAT-Recon-CredentialStuffingValidationSweep Credential Stuffing Validation Sweep (Pre-Attack Breach List Testing)
- THREAT-Recon-DistributedPortScanSweep Distributed Low-and-Slow Port/Service Scanning Sweep
- THREAT-Recon-DistributedVulnScanBurst Distributed Vulnerability Scanning Burst Against Web Infrastructure
- THREAT-Recon-DNSSubdomainWordlistEnumeration DNS Subdomain Wordlist Brute-Force Enumeration
- THREAT-Recon-DNSZoneTransferReconAttempt Unauthorized DNS Zone Transfer (AXFR) and Bulk Record Enumeration Against Authoritative Nameservers
- THREAT-Recon-ExternalVulnScannerBurstDetection External Vulnerability Scanner Burst/Sweep Against Internet-Facing Assets
- THREAT-Recon-PretextingHelpdeskInfoGathering Pretexting and Phishing for Information via Helpdesk Social Engineering
- THREAT-Recon-PretextingReconEmailTrackingBeacon Pretexting Reconnaissance Email with Tracking Pixel / Beacon Link
- THREAT-Recon-SubdomainBruteforceNXDOMAINStorm Subdomain Bruteforce Causing NXDOMAIN Storm
- THREAT-Recon-VishingPretextEmailFollowup Low-Signal Pretext Email Followed by Voice Phishing Call to Same Target
Related tactics
292 detections
276 detections