| Technique | Gather Victim Network Information (T1590) |
| Tactic | Reconnaissance |
| Platforms | PRE |
Detection Playbooks
Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.
Detection Playbook: Employee Names (T1589.003)
| Technique | Employee Names (T1589.003) |
| Tactic | Reconnaissance |
| Platforms | PRE |
Detection Playbook: Email Addresses (T1589.002)
| Technique | Email Addresses (T1589.002) |
| Tactic | Reconnaissance |
| Platforms | PRE |
Detection Playbook: Credentials (T1589.001)
| Technique | Credentials (T1589.001) |
| Tactic | Reconnaissance |
| Platforms | PRE |
Detection Playbook: Gather Victim Identity Information (T1589)
| Technique | Gather Victim Identity Information (T1589) |
| Tactic | Reconnaissance |
| Platforms | PRE |
Detection Playbook: Virtualization/Sandbox Evasion (T1497)
Virtualization/Sandbox Evasion (T1497) describes a class of techniques where malware actively probes its execution environment to determine whether it is run…
Detection Playbook: Ingress Tool Transfer (T1105)
Ingress Tool Transfer (T1105) describes the technique where adversaries download or copy tools, scripts, or payloads from an external system they control int…
Detection Playbook: Exploit Public-Facing Application (T1190)
Exploit Public-Facing Application (T1190) describes adversaries gaining initial access by attacking a vulnerability — a software bug, misconfiguration, or un…
Detection Playbook: Drive-by Compromise (T1189)
Drive-by Compromise (T1189) is an initial access technique where an attacker causes a victim to gain code execution on their system simply by visiting a mali…
Detection Playbook: Exfiltration Over Alternative Protocol (T1048)
Exfiltration Over Alternative Protocol (T1048) describes adversaries stealing data by sending it out through a network protocol that differs from their prima…