1200KM / simulation
T1046 Network Service Discovery — Attack Simulation
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if…
Technique description
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system. Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Port-Scanning /24 Subnet with PowerShell
Procedure 05df2a79-dba6-4088-a804-9ca0802ca8e4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Network Service Discovery for Containers
Procedure 06eaafdb-8982-426e-8a31-d572da633caa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Port Scan using nmap (Port range)
Procedure 0d5a2b03-3a26-45e4-96ae-89485b4d1f97; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - bluekeep
Procedure 1cca5640-32a9-46e6-b8e0-fabbe2384a73; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Port Scan using RustScan (Port list)
Procedure 32c268dd-96a7-4530-817c-848534a39d09; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Port Scan Nmap
Procedure 515942b0-a09f-4163-a7bb-22fefb6f185f; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - spoolvulnscan
Procedure 54574908-f1de-4356-9021-8053dd57439a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Port Scan
Procedure 68e907da-2539-48f6-9fc9-257a78c05540; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Port Scan using python
Procedure 6ca45b04-9f15-4424-b9d3-84a217285a5c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - MS17-10
Procedure 97585b04-5be2-40e9-8c31-82157b8af2d6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Remote Desktop Services Discovery via PowerShell
Procedure 9e55750e-4cbf-4013-9627-e9a045b541bf; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - fruit
Procedure bb037826-cbe8-4a41-93ea-b94059d6bb98; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Port Scan NMap for Windows
Procedure d696a3cb-d7a8-4976-8eb5-5af4abf2e3df; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Naikon · G0019
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- FIN6 · G0037
- Suckfly · G0039
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- Leafminer · G0077
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT39 · G0087
- APT41 · G0096
- BlackTech · G0098
- DarkVishnya · G0105
- Rocke · G0106
- Chimera · G0114
- Fox Kitten · G0117
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- TeamTNT · G0139
- Ember Bear · G1003
- FIN13 · G1016
- Volt Typhoon · G1017
- Agrius · G1030
- INC Ransom · G1032
- RedCurl · G1039
- BlackByte · G1043
- Medusa Group · G1051
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.