{"id":"T1595.001","name":"Scanning IP Blocks","url":"https://attack.mitre.org/techniques/T1595/001","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0817","stix_id":"x-mitre-detection-strategy--ca916010-7f72-4132-ad7c-44967d479dcc","name":"Detection of Scanning IP Blocks","url":"https://attack.mitre.org/detectionstrategies/DET0817","analytics":[{"id":"AN1949","stix_id":"x-mitre-analytic--4ba33f5f-5f75-40c5-96ab-b014e772f9a8","name":"Analytic 1949","description":"Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network.\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.","url":"https://attack.mitre.org/detectionstrategies/DET0817#AN1949","platforms":["PRE"],"log_source_references":[{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"},{"name":"Network Traffic","channel":"None","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"network-traffic"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0817"],"techniques":["T1595.001"]}],"live":true,"version":"1.0","techniques":["T1595.001"]}],"sigma_rules":[{"id":"af688c76-4ce4-4309-bfdd-e896f01acf27","title":"Grixba Malware Reconnaissance Activity","author":"yxinmiracle, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-26","modified":null,"description":"Detects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations.\nThis tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.\n","references":["https://fieldeffect.com/blog/grixba-play-ransomware-impersonates-sentinelone","https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.reconnaissance","attack.t1595.001","attack.discovery","attack.t1046","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Grixba/proc_creation_win_malware_grixba_recon.yml","techniques":["T1595.001","T1046"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}