1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1046 Network Service Discovery — Detection Rules

Detection workspace for T1046 Network Service Discovery: 19 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1046 Network Service Discovery

DISTINCT_COUNT(destination_port OR destination_host BY source_host, 5m) >= threshold -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0376 Behavioral Detection Strategy for Network Service Discovery Across Platforms

AN1057 Analytic 1057

Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.

AN1058 Analytic 1058

Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.

AN1059 Analytic 1059

Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.

AN1060 Analytic 1060

Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1046 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.