Skip to content
Every technique
T0846.001Not expressible in SigmaICS

Port Scan

Discovery

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for ICS. MITRE's telemetry here is operational historians and controller state, which no Sigma rule can address.

What the technique is

Adversaries may perform a port scan on a system, device, or network to identify live hosts, enumerate open ports and running services, identify operating systems, and map out the network. The results of a port scan may inform adversary Discovery, Lateral Movement, and vulnerability exploitation decisions (Exploitation for Evasion, Exploitation for Privilege Escalation, Exploitation of Remote Services). Some common tools for executing a port scan include nmap, netcat, and the Advanced Port Scanner.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN2050

    Monitor for new processes engaging in scanning activity or connecting to multiple systems by correlating process creation network data. Monitor for hosts enumerating network connected resources using non-ICS enterprise protocols.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.