Techniques › T1594 › AN1942
AN1942 Analytic 1942
PRE · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Monitor for suspicious network traffic that could be indicative of adversary reconnaissance, such as rapid successions of requests indicative of web crawling and/or large quantities of requests originating from a single source (especially if the source is known to be associated with an adversary). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.</p>
- Detects
- T1594 Search Victim-Owned Websites
- Part of
- DET0810 Detection of Search Victim-Owned Websites
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Application Log | None | DC0038 Application Log Content |