{"id":"T1594","name":"Search Victim-Owned Websites","url":"https://attack.mitre.org/techniques/T1594","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0810","stix_id":"x-mitre-detection-strategy--52cee5e7-a92e-433e-9b56-38c8f7b16264","name":"Detection of Search Victim-Owned Websites","url":"https://attack.mitre.org/detectionstrategies/DET0810","analytics":[{"id":"AN1942","stix_id":"x-mitre-analytic--5c5afe0d-b967-49ac-8c3e-eeb9cc01667d","name":"Analytic 1942","description":"Monitor for suspicious network traffic that could be indicative of adversary reconnaissance, such as rapid successions of requests indicative of web crawling and/or large quantities of requests originating from a single source (especially if the source is known to be associated with an adversary). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.","url":"https://attack.mitre.org/detectionstrategies/DET0810#AN1942","platforms":["PRE"],"log_source_references":[{"name":"Application Log","channel":"None","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-log"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0810"],"techniques":["T1594"]}],"live":true,"version":"1.0","techniques":["T1594"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}