Reconnaissance
The adversary
is trying to gather information they can use to plan future operations.
Reconnaissance
consists of techniques that involve adversaries actively or passively gathering
information that can be used to support targeting. Such information may include
details of the victim organization, infrastructure, or staff/personnel. This
information can be leveraged by the adversary to aid in other phases of the
adversary lifecycle, such as using gathered information to plan and execute
Initial Access, to scope and prioritize post-compromise objectives, or to drive
and lead further Reconnaissance efforts.
|
ID |
Name |
Description |
|
|
Adversaries may execute active reconnaissance
scans to gather information that can be used during targeting. Active scans
are those where the adversary probes victim infrastructure via network
traffic, as opposed to other forms of reconnaissance that do not involve
direct interaction. |
|||
|
Adversaries may scan victim IP blocks to gather
information that can be used during targeting. Public IP addresses may be
allocated to organizations by block, or a range of sequential addresses. |
|||
|
Adversaries may scan victims for vulnerabilities
that can be used during targeting. Vulnerability scans typically check if the
configuration of a target host/application (ex: software and version)
potentially aligns with the target of a specific exploit the adversary may
seek to use. |
|||
|
Adversaries may iteratively probe infrastructure
using brute-forcing and crawling techniques. While this technique employs
similar methods to Brute Force, its goal is the identification
of content and infrastructure rather than the discovery of valid credentials.
Wordlists used in these scans may contain generic, commonly used names and
file extensions or terms specific to a particular software. Adversaries may
also create custom, target-specific wordlists using data gathered from other
Reconnaissance techniques (ex: Gather
Victim Org Information, or Search
Victim-Owned Websites). |
|||
|
Adversaries may gather information about the
victim's hosts that can be used during targeting. Information about hosts may
include a variety of details, including administrative data (ex: name,
assigned IP, functionality, etc.) as well as specifics regarding its
configuration (ex: operating system, language, etc.). |
|||
|
Adversaries may gather information about the
victim's host hardware that can be used during targeting. Information about
hardware infrastructure may include a variety of details such as types and
versions on specific hosts, as well as the presence of additional components
that might be indicative of added defensive protections (ex: card/biometric
readers, dedicated encryption hardware, etc.). |
|||
|
Adversaries may gather information about the
victim's host software that can be used during targeting. Information about
installed software may include a variety of details such as types and
versions on specific hosts, as well as the presence of additional components
that might be indicative of added defensive protections (ex: antivirus,
SIEMs, etc.). |
|||
|
Adversaries may gather information about the
victim's host firmware that can be used during targeting. Information about
host firmware may include a variety of details such as type and versions on
specific hosts, which may be used to infer more information about hosts in
the environment (ex: configuration, purpose, age/patch level, etc.). |
|||
|
Adversaries may gather information about the
victim's client configurations that can be used during targeting. Information
about client configurations may include a variety of details and settings,
including operating system/version, virtualization, architecture (ex: 32 or
64 bit), language, and/or time zone. |
|||
|
Adversaries may gather information about the
victim's identity that can be used during targeting. Information about
identities may include a variety of details, including personal data (ex:
employee names, email addresses, etc.) as well as sensitive details such as
credentials. |
|||
|
Adversaries may gather credentials that can be
used during targeting. Account credentials gathered by adversaries may be
those directly associated with the target victim organization or attempt to
take advantage of the tendency for users to use the same passwords across
personal and business accounts. |
|||
|
Adversaries may gather email addresses that can be
used during targeting. Even if internal instances exist, organizations may
have public-facing email infrastructure and addresses for employees. |
|||
|
Adversaries may gather employee names that can be
used during targeting. Employee names be used to derive email addresses as
well as to help guide other reconnaissance efforts and/or craft
more-believable lures. |
|||
|
Adversaries may gather information about the
victim's networks that can be used during targeting. Information about
networks may include a variety of details, including administrative data (ex:
IP ranges, domain names, etc.) as well as specifics regarding its topology
and operations. |
|||
|
Adversaries may gather information about the
victim's network domain(s) that can be used during targeting. Information
about domains and their properties may include a variety of details,
including what domain(s) the victim owns as well as administrative data (ex:
name, registrar, etc.) and more directly actionable information such as
contacts (email addresses and phone numbers), business addresses, and name
servers. |
|||
|
Adversaries may gather information about the
victim's DNS that can be used during targeting. DNS information may include a
variety of details, including registered name servers as well as records that
outline addressing for a target’s subdomains, mail servers, and other hosts.
DNS, MX, TXT, and SPF records may also reveal the use of third party cloud
and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk. |
|||
|
Adversaries may gather information about the
victim's network trust dependencies that can be used during targeting.
Information about network trusts may include a variety of details, including
second or third-party organizations/domains (ex: managed service providers,
contractors, etc.) that have connected (and potentially elevated) network
access. |
|||
|
Adversaries may gather information about the
victim's network topology that can be used during targeting. Information
about network topologies may include a variety of details, including the
physical and/or logical arrangement of both external-facing and internal
network environments. This information may also include specifics regarding
network devices (gateways, routers, etc.) and other infrastructure. |
|||
|
Adversaries may gather the victim's IP addresses
that can be used during targeting. Public IP addresses may be allocated to
organizations by block, or a range of sequential addresses. Information about
assigned IP addresses may include a variety of details, such as which IP
addresses are in use. IP addresses may also enable an adversary to derive
other details about a victim, such as organizational size, physical
location(s), Internet service provider, and or where/how their
publicly-facing infrastructure is hosted. |
|||
|
Adversaries may gather information about the
victim's network security appliances that can be used during targeting.
Information about network security appliances may include a variety of
details, such as the existence and specifics of deployed firewalls, content
filters, and proxies/bastion hosts. Adversaries may also target information
about victim network-based intrusion detection systems (NIDS) or other
appliances related to defensive cybersecurity operations. |
|||
|
Adversaries may gather information about the
victim's organization that can be used during targeting. Information about an
organization may include a variety of details, including the names of
divisions/departments, specifics of business operations, as well as the roles
and responsibilities of key employees. |
|||
|
Adversaries may gather the victim's physical
location(s) that can be used during targeting. Information about physical
locations of a target organization may include a variety of details,
including where key resources and infrastructure are housed. Physical
locations may also indicate what legal jurisdiction and/or authorities the
victim operates within. |
|||
|
Adversaries may gather information about the
victim's business relationships that can be used during targeting.
Information about an organization’s business relationships may include a
variety of details, including second or third-party organizations/domains
(ex: managed service providers, contractors, etc.) that have connected (and
potentially elevated) network access. This information may also reveal supply
chains and shipment paths for the victim’s hardware and software resources. |
|||
|
Adversaries may gather information about the
victim's business tempo that can be used during targeting. Information about
an organization’s business tempo may include a variety of details, including
operational hours/days of the week. This information may also reveal
times/dates of purchases and shipments of the victim’s hardware and software
resources. |
|||
|
Adversaries may gather information about
identities and roles within the victim organization that can be used during
targeting. Information about business roles may reveal a variety of
targetable details, including identifiable information for key personnel as
well as what data/resources they have access to. |
|||
|
Adversaries may send phishing messages to elicit
sensitive information that can be used during targeting. Phishing for
information is an attempt to trick targets into divulging information,
frequently credentials or other actionable information. Phishing for
information is different from Phishing in
that the objective is gathering data from the victim rather than executing
malicious code. |
|||
|
Adversaries may send spearphishing messages via
third-party services to elicit sensitive information that can be used during
targeting. Spearphishing for information is an attempt to trick targets into
divulging information, frequently credentials or other actionable
information. Spearphishing for information frequently involves social
engineering techniques, such as posing as a source with a reason to collect
information (ex: Establish Accounts or Compromise
Accounts) and/or sending multiple, seemingly urgent messages. |
|||
|
Adversaries may send spearphishing messages with a
malicious attachment to elicit sensitive information that can be used during
targeting. Spearphishing for information is an attempt to trick targets into
divulging information, frequently credentials or other actionable
information. Spearphishing for information frequently involves social
engineering techniques, such as posing as a source with a reason to collect
information (ex: Establish Accounts or Compromise
Accounts) and/or sending multiple, seemingly urgent messages. |
|||
|
Adversaries may send spearphishing messages with a
malicious link to elicit sensitive information that can be used during
targeting. Spearphishing for information is an attempt to trick targets into
divulging information, frequently credentials or other actionable
information. Spearphishing for information frequently involves social
engineering techniques, such as posing as a source with a reason to collect
information (ex: Establish Accounts or Compromise
Accounts) and/or sending multiple, seemingly urgent messages. |
|||
|
Adversaries may search and gather information
about victims from closed sources that can be used during targeting.
Information about victims may be available for purchase from reputable
private sources and databases, such as paid subscriptions to feeds of
technical/threat intelligence data. Adversaries may also purchase information
from less-reputable sources such as dark web or cybercrime blackmarkets. |
|||
|
Adversaries may search private data from threat
intelligence vendors for information that can be used during targeting.
Threat intelligence vendors may offer paid feeds or portals that offer more
data than what is publicly reported. Although sensitive details (such as
customer names and other identifiers) may be redacted, this information may
contain trends regarding breaches such as target industries, attribution
claims, and successful TTPs/countermeasures. |
|||
|
Adversaries may purchase technical information
about victims that can be used during targeting. Information about victims
may be available for purchase within reputable private sources and databases,
such as paid subscriptions to feeds of scan databases or other data
aggregation services. Adversaries may also purchase information from
less-reputable sources such as dark web or cybercrime blackmarkets. |
|||
|
Adversaries may search freely available technical
databases for information about victims that can be used during targeting.
Information about victims may be available in online databases and
repositories, such as registrations of domains/certificates as well as public
collections of network data/artifacts gathered from traffic and/or scans. |
|||
|
Adversaries may search DNS data for information
about victims that can be used during targeting. DNS information may include
a variety of details, including registered name servers as well as records
that outline addressing for a target’s subdomains, mail servers, and other
hosts. |
|||
|
Adversaries may search public WHOIS data for
information about victims that can be used during targeting. WHOIS data is
stored by regional Internet registries (RIR) responsible for allocating and
assigning Internet resources such as domain names. Anyone can query WHOIS
servers for information about a registered domain, such as assigned IP
blocks, contact information, and DNS nameservers. |
|||
|
Adversaries may search public digital certificate
data for information about victims that can be used during targeting. Digital
certificates are issued by a certificate authority (CA) in order to
cryptographically verify the origin of signed content. These certificates,
such as those used for encrypted web traffic (HTTPS SSL/TLS communications),
contain information about the registered organization such as name and
location. |
|||
|
Adversaries may search content delivery network
(CDN) data about victims that can be used during targeting. CDNs allow an
organization to host content from a distributed, load balanced array of
servers. CDNs may also allow organizations to customize content delivery
based on the requestor’s geographical region. |
|||
|
Adversaries may search within public scan
databases for information about victims that can be used during targeting.
Various online services continuously publish the results of Internet
scans/surveys, often harvesting information such as active IP addresses,
hostnames, open ports, certificates, and even server banners. |
|||
|
Adversaries may search freely available websites
and/or domains for information about victims that can be used during
targeting. Information about victims may be available in various online
sites, such as social media, new sites, or those hosting information about
business operations such as hiring or requested/rewarded contracts. |
|||
|
Adversaries may search social media for
information about victims that can be used during targeting. Social media
sites may contain various information about a victim organization, such as
business announcements as well as information about the roles, locations, and
interests of staff. |
|||
|
Adversaries may use search engines to collect
information about victims that can be used during targeting. Search engine
services typical crawl online sites to index context and may provide users
with specialized syntax to search for specific keywords or specific types of
content (i.e. filetypes). |
|||
|
Adversaries may search public code repositories
for information about victims that can be used during targeting. Victims may
store code in repositories on various third-party websites such as GitHub,
GitLab, SourceForge, and BitBucket. Users typically interact with code
repositories through a web application or command-line utilities such as git. |
|||
|
Adversaries may search websites owned by the
victim for information that can be used during targeting. Victim-owned
websites may contain a variety of details, including names of
departments/divisions, physical locations, and data about key employees such
as names, roles, and contact info (ex: Email
Addresses). These sites may also have details highlighting
business operations and relationships. |
|||
沒有留言:
張貼留言