1200KM / detection
T1018 Remote System Discovery — Detection Rules
Detection workspace for T1018 Remote System Discovery: 16 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Linux Remote System Discovery · test · low · {"category":"process_creation","product":"linux"}
- Macos Remote System Discovery · test · informational · {"category":"process_creation","product":"macos"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- DirectorySearcher Powershell Exploitation · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Active Directory Computers Enumeration With Get-AdComputer · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock · experimental · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enable"}
- HackTool - NetExec Execution · experimental · high · {"category":"process_creation","product":"windows"}
- Share And Session Enumeration Using Net.EXE · stable · low · {"category":"process_creation","product":"windows"}
- Nltest.EXE Execution · test · low · {"category":"process_creation","product":"windows"}
- PUA - AdFind Suspicious Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Adidnsdump Execution · test · low · {"category":"process_creation","product":"windows"}
- Renamed AdFind Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Scan Loop Network · test · medium · {"category":"process_creation","product":"windows"}
- Chopper Webshell Process Pattern · test · high · {"category":"process_creation","product":"windows"}
- Webshell Hacking Activity Patterns · test · high · {"category":"process_creation","product":"windows"}
- Webshell Detection With Command Line Keywords · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0574 Detection Strategy for Remote System Enumeration Behavior
AN1583 Analytic 1583
Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.
AN1584 Analytic 1584
Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts.
AN1585 Analytic 1585
Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents.
AN1586 Analytic 1586
ESXi shell or SSH access issuing `esxcli network diag ping` or viewing routing tables to identify connected hosts.
AN1587 Analytic 1587
Execution of discovery commands like `show cdp neighbors`, `show arp`, and other interface-level introspection on Cisco or Juniper devices.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- Deep Panda · G0009
- Turla · G0010
- Naikon · G0019
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Sandworm Team · G0034
- Dragonfly · G0035
- FIN6 · G0037
- menuPass · G0045
- APT32 · G0050
- FIN5 · G0053
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- Leafminer · G0077
- APT39 · G0087
- Silence · G0091
- GALLIUM · G0093
- APT41 · G0096
- Wizard Spider · G0102
- Rocke · G0106
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- HAFNIUM · G0125
- Mustang Panda · G0129
- HEXANE · G1001
- Ember Bear · G1003
- Earth Lusca · G1006
- Scattered Spider · G1015
- Volt Typhoon · G1017
- ToddyCat · G1022
- Akira · G1024
- Agrius · G1030
- Play · G1040
- BlackByte · G1043
- Medusa Group · G1051
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.