Meta tags:
Headings (most frequently used words):
gather, victim, network, information, ip, addresses, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,
Text of the page (most frequently used words):
#addresses (14), the (11), att (10), all (10), may (9), t1590 (9), information (9), enterprise (8), and (7), #network (7), detection (6), october (6), retrieved (6), gather (6), victim (6), ics (5), mobile (5), none (5), data (5), techniques (5), for (5), mitre (4), defenses (4), sub (4), 2021 (4), such (4), this (4), version (4), about (4), other (4), are (3), domains (3), resources (3), cti (3), mitigations (3), exchange (3), active (3), andariel (3), dns (3), 2020 (3), description (3), name (3), technique (3), has (3), 005 (3), adversaries (3), infrastructure (3), search (3), open (3), details (3), 2026 (2), corporation (2), use (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), march (2), attacks (2), target (2), efforts (2), adversary (2), during (2), initial (2), access (2), outside (2), analytic (2), with (2), controls (2), external (2), pre (2), compromise (2), their (2), phishing (2), magic (2), hound (2), publicly (2), accessible (2), hafnium (2), reconnaissance (2), via (2), assigned (2), also (2), scanning (2), can (2), location (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, bash, countering, threats, from, iran, january, 2023, gruzweig, operation, marauder, exploitation, multiple, zero, day, microsoft, vulnerabilities, ahnlab, 2018, june, targeted, threat, group, subgroup, lazarus, september, circl, computer, incident, response, center, passive, hacker, dumpster, ntt, america, whois, lookup, november, 2024, references, focused, related, stages, lifecycle, much, activity, have, very, high, occurrence, associated, false, positive, rate, well, potentially, taking, place, visibility, organization, making, difficult, defenders, an1947, det0815, strategy, cannot, easily, mitigated, preventive, since, based, behaviors, performed, scope, should, focus, minimizing, amount, sensitivity, available, parties, m1056, mitigation, captured, visitors, sites, g0059, obtained, servers, g0125, limited, its, watering, hole, specific, address, ranges, g0138, procedure, examples, live, permalink, 2025, last, modified, created, platforms, tactic, various, ways, direct, collection, actions, exposed, online, sets, gathering, reveal, opportunities, forms, establishing, operational, remote, services, acquire, websites, technical, databases, that, used, targeting, public, allocated, organizations, block, range, sequential, include, variety, which, enable, derive, organizational, size, physical, internet, service, provider, where, how, facing, hosted, security, appliances, 006, topology, 004, trust, dependencies, 003, 002, domain, properties, 001, home, join, mclean, hotel, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, get, started, detections,
Text of the page (random words):
gather victim network information ip addresses sub technique t1590 005 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise gather victim network information ip addresses gather victim network information ip addresses other sub techniques of gather victim network information 6 id name t1590 001 domain properties t1590 002 dns t1590 003 network trust dependencies t1590 004 network topology t1590 005 ip addresses t1590 006 network security appliances adversaries may gather the victim s ip addresses that can be used during targeting public ip addresses may be allocated to organizations by block or a range of sequential addresses information about assigned ip addresses may include a variety of details such as which ip addresses are in use ip addresses may also enable an adversary to derive other details about a victim such as organizational size physical location s internet service provider and or where how their publicly facing infrastructure is hosted adversaries may gather this information in various ways such as direct collection actions via active scanning or phishing for information information about assigned ip addresses may also be exposed to adversaries via online or other accessible data sets ex search open technical databases 1 2 3 gathering this information may reveal opportunities for other forms of reconnaissance ex active scanning or search open websites domains establishing operational resources ex acquire infrastructure or compromise infrastructure and or initial access ex external remote services id t1590 005 sub technique of t1590 ⓘ tactic reconnaissance ⓘ platforms pre version 1 0 created 02 october 2020 last modified 24 october 2025 version permalink live version procedure examples id name description g0138 andariel andariel has limited its watering hole attacks to specific ip address ranges 4 g0125 hafnium hafnium has obtained ip addresses for publicly accessible exchange servers 5 g0059 magic hound magic hound has captured the ip addresses of visitors to their phishing sites 6 mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls efforts should focus on minimizing the amount and sensitivity of data available to external parties detection strategy id name analytic id analytic description det0815 detection of ip addresses an1947 much of this activity may have a very high occurrence and associated false positive rate as well as potentially taking place outside the visibility of the target organization making detection difficult for defenders detection efforts may be focused on related stages of the adversary lifecycle such as during initial access references ntt america n d whois lookup retrieved november 17 2024 hacker target n d dns dumpster retrieved october 20 2020 circl computer incident response center n d passive dns retrieved october 20 2020 ahnlab 2018 june 23 targeted attacks by andariel threat group a subgroup of the lazarus retrieved september 29 2021 gruzweig j et al 2021 march 2 operation exchange marauder active exploitation of multiple zero day microsoft exchange vulnerabilities retrieved march 3 2021 bash a 2021 october 14 countering threats from iran retrieved january 4 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|