If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1590 - Gather Victim Network Informat.

site address: attack.mitre.org/techniques/T1590 redirected to: attack.mitre.org/techniques/T1590

site title: Gather Victim Network Information, Technique T1590 - Enterprise MITRE ATT&CK®

Our opinion (on Wednesday 12 August 2026 2:40:07 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

gather, victim, network, information, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
the (15), t1590 (14), #information (11), att (10), and (10), all (10), network (9), enterprise (8), may (8), #victim (8), data (6), detection (6), techniques (6), retrieved (6), gather (6), about (6), ics (5), mobile (5), none (5), october (5), for (5), mitre (4), defenses (4), 2024 (4), compromise (4), this (4), reconnaissance (4), version (4), domains (3), resources (3), cti (3), mitigations (3), sub (3), access (3), infrastructure (3), exchange (3), active (3), dns (3), 2020 (3), target (3), such (3), description (3), name (3), pre (3), has (3), indrik (3), spider (3), domain (3), adversaries (3), networks (3), search (3), open (3), 2026 (2), corporation (2), are (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), 2021 (2), march (2), efforts (2), during (2), initial (2), well (2), outside (2), organization (2), analytic (2), technique (2), with (2), controls (2), learn (2), volt (2), typhoon (2), tools (2), also (2), etc (2), names (2), hafnium (2), 006 (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), via (2), other (2), scanning (2), can (2), details (2), topology (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, use, contact, reset, filters, cisa, february, prc, state, sponsored, actors, maintain, persistent, critical, mandiant, intelligence, 2022, june, hades, back, unc2165, shifts, lockbit, evade, sanctions, july, gruzweig, operation, marauder, exploitation, multiple, zero, day, microsoft, vulnerabilities, circl, computer, incident, response, center, passive, hacker, dumpster, ntt, america, whois, lookup, november, references, focused, related, stages, adversary, lifecycle, much, activity, have, very, high, occurrence, associated, false, positive, rate, potentially, taking, place, visibility, making, difficult, defenders, an2001, det0869, strategy, cannot, easily, mitigated, preventive, since, based, behaviors, performed, scope, should, focus, minimizing, amount, sensitivity, available, external, parties, m1056, mitigation, conducted, extensive, g1017, downloaded, advanced, port, scanner, utility, lansweeper, conduct, internal, accessed, vmware, vcenter, which, had, host, configuration, clusters, g0119, gathered, fully, qualified, fqdns, targeted, servers, environment, g0125, procedure, examples, live, permalink, 2025, last, modified, created, platforms, tactic, various, ways, direct, collection, actions, exposed, online, accessible, sets, gathering, reveal, opportunities, forms, establishing, operational, trusted, relationship, acquire, websites, technical, databases, phishing, that, used, targeting, include, variety, including, administrative, ranges, specifics, regarding, its, operations, security, appliances, addresses, trust, dependencies, properties, home, join, mclean, hotel, location, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, more, get, started, detections,


Text of the page (random words):
gather victim network information technique t1590 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise gather victim network information gather victim network information sub techniques 6 id name t1590 001 domain properties t1590 002 dns t1590 003 network trust dependencies t1590 004 network topology t1590 005 ip addresses t1590 006 network security appliances adversaries may gather information about the victim s networks that can be used during targeting information about networks may include a variety of details including administrative data ex ip ranges domain names etc as well as specifics regarding its topology and operations adversaries may gather this information in various ways such as direct collection actions via active scanning or phishing for information information about networks may also be exposed to adversaries via online or other accessible data sets ex search open technical databases 1 2 3 gathering this information may reveal opportunities for other forms of reconnaissance ex active scanning or search open websites domains establishing operational resources ex acquire infrastructure or compromise infrastructure and or initial access ex trusted relationship id t1590 sub techniques t1590 001 t1590 002 t1590 003 t1590 004 t1590 005 t1590 006 ⓘ tactic reconnaissance ⓘ platforms pre version 1 0 created 02 october 2020 last modified 24 october 2025 version permalink live version procedure examples id name description g0125 hafnium hafnium gathered the fully qualified domain names fqdns for targeted exchange servers in the victim s environment 4 g0119 indrik spider indrik spider has downloaded tools such as the advanced port scanner utility and lansweeper to conduct internal reconnaissance of the victim network indrik spider has also accessed the victim s vmware vcenter which had information about host configuration clusters etc 5 g1017 volt typhoon volt typhoon has conducted extensive pre compromise reconnaissance to learn about the target organization s network 6 mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls efforts should focus on minimizing the amount and sensitivity of data available to external parties detection strategy id name analytic id analytic description det0869 detection of gather victim network information an2001 much of this activity may have a very high occurrence and associated false positive rate as well as potentially taking place outside the visibility of the target organization making detection difficult for defenders detection efforts may be focused on related stages of the adversary lifecycle such as during initial access references ntt america n d whois lookup retrieved november 17 2024 hacker target n d dns dumpster retrieved october 20 2020 circl computer incident response center n d passive dns retrieved october 20 2020 gruzweig j et al 2021 march 2 operation exchange marauder active exploitation of multiple zero day microsoft exchange vulnerabilities retrieved march 3 2021 mandiant intelligence 2022 june 2 to hades and back unc2165 shifts to lockbit to evade sanctions retrieved july 29 2024 cisa et al 2024 february 7 prc state sponsored actors compromise and maintain persistent access to u s critical infrastructure retrieved may 15 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 67 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-67


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 www.cisa.gov/sites/default/files/2024-___.pdf  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1590
X-GitHub-Request-Id C28A:3CF574:82CFF:89617:6A7BDD04
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Wed, 12 Aug 2026 02:40:07 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630097-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786502407.155014,VS0,VE80
Vary Accept-Encoding
X-Fastly-Request-ID 4842e607b15c24173ab77ced9ed84815ada3402e
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1590/
access-control-allow-origin *
expires Wed, 12 Aug 2026 02:50:07 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 6A66:905C9:81C57:88559:6A7BDD06
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Wed, 12 Aug 2026 02:40:07 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630068-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786502407.263632,VS0,VE85
vary Accept-Encoding
x-fastly-request-id c7da55363886c7490d5b0b1df9c0473ded4aa4fd
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-badb
expires Wed, 12 Aug 2026 02:50:07 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 09D4:3AB2D3:7D917:84256:6A7BDD06
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Wed, 12 Aug 2026 02:40:07 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630068-LCY
x-cache MISS
x-cache-hits 0
x-timer S1786502407.356761,VS0,VE94
vary Accept-Encoding
x-fastly-request-id 21bbc928ad1efb500acbdee2e431ba7bd7f4e4f1
content-length 7961

Meta Tags

title="Gather Victim Network Information, Technique T1590 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size7961
load time (s)0.528241
redirect count2
speed download15077
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"