TACTIC: DISCOVERY

Network Service Discovery (T1046): real cases

MITRE Definition ↗
Adversaries scan network IP ranges to identify open ports, listening services, and exploitable servers.

Key Facts

Technique ID
T1046
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1046.
  • Tactical Phase: Discovery.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Trial Transcript Day 4, Page 82
"Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389."
U.S. District Court for the Western District of Washington View full case dossier →