Loading interactive filters…
1200KM / detection
T1046 Network Service Discovery — Detection Rules
Detection workspace for T1046 Network Service Discovery: 19 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - NMAP FIN Scan · experimental · high · {"category":"application","product":"opencanary"}
- OpenCanary - NMAP NULL Scan · experimental · high · {"category":"application","product":"opencanary"}
- OpenCanary - NMAP OS Scan · experimental · high · {"category":"application","product":"opencanary"}
- OpenCanary - NMAP XMAS Scan · experimental · high · {"category":"application","product":"opencanary"}
- OpenCanary - Host Port Scan (SYN Scan) · experimental · high · {"category":"application","product":"opencanary"}
- Linux Network Service Scanning - Auditd · test · low · {"product":"linux","service":"auditd","definition":"Configure these rules https://github.com/Neo23x0/auditd/blob/e181243a7c708e9d579557d6f80e0ed3d3483b89/audit.rules#L182-L183"}
- Pnscan Binary Data Transmission Activity · test · medium · {"category":"process_creation","product":"linux"}
- Linux Network Service Scanning Tools Execution · test · low · {"category":"process_creation","product":"linux"}
- MacOS Network Service Scanning · test · low · {"category":"process_creation","product":"macos"}
- Advanced IP Scanner - File Event · test · medium · {"category":"file_event","product":"windows"}
- Python Initiated Connection · test · medium · {"category":"network_connection","product":"windows","definition":"Requirements: Field enrichment is required for the filters to work. As field such as CommandLine and ParentImage are not available by default on this event type"}
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - winPEAS Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Advanced IP Scanner Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - Advanced Port Scanner Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - SoftPerfect Netscan Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - NimScan Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - Nmap/Zenmap Execution · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1046 Network Service Discovery
DISTINCT_COUNT(destination_port OR destination_host BY source_host, 5m) >= threshold -> ALERT
Anomaly models
Internal network services or systems scanned — T1046 Network Service Discovery
Comparison unit: internal source host.
Expected behavior: hosts communicate with a stable peer and service set.
Deviation: rapid fan-out across destinations or ports and abrupt graph growth.
ATT&CK analytic guidance
Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.
Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.
Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.
Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.