Search Open Technical Databases
Description
Adversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be available in online databases and repositories, such as registrations of domains/certificates as well as public collections of network data/artifacts gathered from traffic and/or scans.(Citation: WHOIS)(Citation: DNS Dumpster)(Citation: Circl Passive DNS)(Citation: Medium SSL Cert)(Citation: SSLShopper Lookup)(Citation: DigitalShadows CDN)(Citation: Shodan) Adversaries may search in different open databases depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: [Phishing for Information](https://attack.mitre.org/techniques/T1598) or [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593)), establishing operational resources (ex: [Acquire Infrastructure](https://attack.mitre.org/techniques/T1583) or [Compromise Infrastructure](https://attack.mitre.org/techniques/T1584)), and/or initial access (ex: [External Remote Services](https://attack.mitre.org/techniques/T1133) or [Trusted Relationship](https://attack.mitre.org/techniques/T1199)).
Mapped SPARTA techniques
2 techniques
Spacecraft identifiers (NORAD/COSPAR/ITU/FCC numbers) are gathered primarily from public technical databases (Space-Track, ITU registries, FCC ULS); T1596 'Search Open Technical Databases' directly addresses this collection method.
Known-vulnerability data is gathered from open technical databases (NVD, CVE, vendor advisories, exploit-DB); T1596 'Search Open Technical Databases' covers the search-channel side of vulnerability reconnaissance, complementary to T1592.002.
Cite as SafeMode Space, mitre-attack-enterprise T1596.