{"id":"T1595.002","name":"Vulnerability Scanning","url":"https://attack.mitre.org/techniques/T1595/002","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0867","stix_id":"x-mitre-detection-strategy--574d055c-4501-4f4d-9b28-1109ad07a087","name":"Detection of Vulnerability Scanning","url":"https://attack.mitre.org/detectionstrategies/DET0867","analytics":[{"id":"AN1999","stix_id":"x-mitre-analytic--f2f01ea3-a59c-42b1-b934-83065ae1f785","name":"Analytic 1999","description":"Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.","url":"https://attack.mitre.org/detectionstrategies/DET0867#AN1999","platforms":["PRE"],"log_source_references":[{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"},{"name":"Network Traffic","channel":"None","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"network-traffic"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0867"],"techniques":["T1595.002"]}],"live":true,"version":"1.0","techniques":["T1595.002"]}],"sigma_rules":[{"id":"aff715fa-4dd5-497a-8db3-910bea555566","title":"DNS Query to External Service Interaction Domains","author":"Florian Roth (Nextron Systems), Matt Kelly (list of domains)","status":"test","level":"high","date":"2022-06-07","modified":"2026-07-23","description":"Detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains.\nThese services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security\nresearchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and\nLog4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain.\n\nA detection indicates that a host on your network resolved one of these domains, which may mean:\n    (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to\n    confirm code execution or data exfiltration,\n    (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets.\n\nInvestigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session),\nand any concurrent outbound connections or process activity to determine intent.\n","references":["https://twitter.com/breakersall/status/1533493587828260866","https://www.bitdefender.com/en-us/blog/businessinsights/bitdefender-advisory-critical-unauthenticated-rce-windows-server-update-services-cve-2025-59287","https://github.com/SigmaHQ/sigma/pull/5724#issuecomment-3466382234","https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve"],"logsource":{"category":"dns"},"tags":["attack.initial-access","attack.t1190","attack.reconnaissance","attack.t1595.002"],"path":"rules/network/dns/net_dns_external_service_interaction_domains.yml","techniques":["T1190","T1595.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}