Loading interactive filters…
1200KM / detection
T1595.003 Wordlist Scanning — Detection Rules
Detection workspace for T1595.003 Wordlist Scanning: 0 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
T1595.003 Wordlist Scanning
COUNT(http_status IN [404, 403] BY source_ip, 5m) >= threshold AND DISTINCT_COUNT(uri_path) >= threshold -> ALERT
Anomaly models
Enumeration of public web paths and APIs — T1595.003 Wordlist Scanning
Comparison unit: client session.
Expected behavior: requests follow common application paths with ordinary response-code proportions.
Deviation: high path diversity, repeated missing-resource responses, and an unusual request composition.
ATT&CK analytic guidance
Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet).
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.