kevmap

TechniquesT1595 › T1595.001

T1595.001 Scanning IP Blocks

reconnaissance — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1595.001
0
KEV CVEs mapped here
<p>Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.</p><p>Adversaries may scan IP blocks in order to Gather Victim Network Information, such as which IP addresses are actively in use as well as more detailed information about hosts assigned these addresses. Scans may range from simple pings (ICMP requests and responses) to more nuanced scans that may reveal host software/versions via server banners or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1595.001

Author: yxinmiracle, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-26 · logsource: product=windows category=process_creation · af688c76-4ce4-4309-bfdd-e896f01acf27
Detects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
Techniques: T1595.001T1046

Rules tagged at the parent level (attack.t1595) 3

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Joseph A. M. · 2025-08-02 · logsource: category=proxy · 1712bafe-be05-4a0e-89d4-17a3ed151bf5
Detects network traffic potentially associated with a scraper botnet variant that uses the "Hello-World/1.0" user-agent string.
Techniques: T1595
Author: Nasreddine Bencherchali (Nextron Systems), frack113 · 2024-01-11 · logsource: product=windows category=process_creation · b1cb4ab6-ac31-43f4-adf1-d9d08957419c
Detects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level.
Techniques: T1595
Author: Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems) · 2024-01-11 · logsource: product=windows category=process_creation · b37998de-a70b-4f33-b219-ec36bf433dc0
Detects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
Techniques: T1595