TACTIC: DISCOVERY
Network Service Discovery (T1046): real cases
MITRE Definition ↗ Adversaries scan network IP ranges to identify open ports, listening services, and exploitable servers.
Key Facts
Technique ID
T1046
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1046.
- Tactical Phase: Discovery.
- Substantiated in 1 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Roman Seleznev (Track2 Point-of-Sale Carding)
sentenced 2011-03-03
Primary Source Evidence Excerpt: Trial Transcript Day 4, Page 82
"Seleznev conducted port scans across internet subnets searching for open and vulnerable Remote Desktop Protocol (RDP) port 3389."
U.S. District Court for the Western District of Washington
View full case dossier →