// MITRE ATT&CK
T1592 · Gather Victim Host Information
🎯 Reconnaissance PRE
Adversaries may gather information about the victim's hosts that can be used during targeting. Information about hosts may include a variety of details, including administrative data (ex: name, assigned IP, functionality, etc.) as well as specifics regarding its configuration (ex: operating system, ...
How to detect & mitigate it
Detecting Gather Victim Host Information starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (4)
Related techniques
T1596.003
Digital Certificates T1597.002
Purchase Technical Data T1590.005
IP Addresses T1590.002
DNS T1682
Query Public AI Services T1596.002
WHOIS T1594
Search Victim-Owned Websites T1596.001
DNS/Passive DNS
Digital Certificates T1597.002
Purchase Technical Data T1590.005
IP Addresses T1590.002
DNS T1682
Query Public AI Services T1596.002
WHOIS T1594
Search Victim-Owned Websites T1596.001
DNS/Passive DNS
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.