Techniques › T1592.004 › AN1952
AN1952 Analytic 1952
PRE · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Internet scanners may be used to look for patterns associated with malicious content designed to collect client configuration information from visitors. Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.</p>
- Detects
- T1592.004 Client Configurations
- Part of
- DET0820 Detection of Client Configurations
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Internet Scan | None | DC0104 Response Content |