{"id":"T1590","name":"Gather Victim Network Information","url":"https://attack.mitre.org/techniques/T1590","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0869","stix_id":"x-mitre-detection-strategy--9031c511-d7ff-410e-9144-d3afee390210","name":"Detection of Gather Victim Network Information","url":"https://attack.mitre.org/detectionstrategies/DET0869","analytics":[{"id":"AN2001","stix_id":"x-mitre-analytic--ca1afe09-7edb-4415-a240-92a0f30ac22f","name":"Analytic 2001","description":"Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.","url":"https://attack.mitre.org/detectionstrategies/DET0869#AN2001","platforms":["PRE"],"log_source_references":[],"mutable_elements":[],"live":true,"detection_strategies":["DET0869"],"techniques":["T1590"]}],"live":true,"version":"1.0","techniques":["T1590"]}],"sigma_rules":[{"id":"1a9bb21a-1bb5-42d7-aa05-3219c7c8f47d","title":"PUA - Advanced IP/Port Scanner Update Check","author":"Axel Olsson","status":"test","level":"medium","date":"2022-08-14","modified":"2024-02-15","description":"Detect the update check performed by Advanced IP/Port Scanner utilities.","references":["https://www.advanced-ip-scanner.com/","https://www.advanced-port-scanner.com/"],"logsource":{"category":"proxy"},"tags":["attack.discovery","attack.reconnaissance","attack.t1590"],"path":"rules/web/proxy_generic/proxy_pua_advanced_ip_scanner_update_check.yml","techniques":["T1590"],"cves":[]},{"id":"ec82e2a5-81ea-4211-a1f8-37a0286df2c2","title":"Suspicious DNS Query for IP Lookup Service APIs","author":"Brandon George (blog post), Thomas Patzke","status":"test","level":"medium","date":"2021-07-08","modified":"2024-03-22","description":"Detects DNS queries for IP lookup services such as \"api.ipify.org\" originating from a non browser process.","references":["https://www.binarydefense.com/analysis-of-hancitor-when-boring-begets-beacon","https://twitter.com/neonprimetime/status/1436376497980428318","https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.reconnaissance","attack.t1590"],"path":"rules/windows/dns_query/dns_query_win_susp_external_ip_lookup.yml","techniques":["T1590"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}