T1595.003: Wordlist Scanning
Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal is the identification of content and infrastructure rather than the discovery of valid credentials. Wordlists used in these scans may contain generic, commonly used names and file extensions or terms specific to a particular software. Adversaries may also create custom, target-specific wordlists using data gathered from other Reconnaissance techniques (ex: Gather Victim Org Information, or Search Victim-Owned Websites).
For example, adversaries may use web content discovery tools such as Dirb, DirBuster, and GoBuster and generic or custom wordlists to enumerate a website’s pages and directories. This can help them to discover old, vulnerable pages or hidden administrative portals that could become the target of further operations (ex: Exploit Public-Facing Application or Brute Force).
As cloud storage solutions typically use globally unique names, adversaries may also use target-specific wordlists and tools such as s3recon and GCPBucketBrute to enumerate public and private buckets on cloud infrastructure. Once storage objects are discovered, adversaries may leverage Data from Cloud Storage to access valuable information that can be exfiltrated or used to escalate privileges and move laterally.
Positive Technologies products that cover the technique
MaxPatrol SIEM knowledge base
web_servers_abnormal_activity: PT-CR-638: Web_Searching_Non_Existent_Artifacts: A failed attempt to get a service artifact web_servers_abnormal_activity: PT-CR-634: Web_Bulk_Failed_URL_Access: Multiple failed attempts to access non-existent pages pt_application_firewall: PT-CR-1883: PTAF_Scanner_Detected: PT AF detected scanner activity in a web application capabilities_suspicious_activity: PT-CR-3059: CAP_Activity_From_Known_Malicious_Hostname: Login attempts from a suspicious host or suspicious activity on a DHCP server. Suspiciousness is determined by the presence in the host network name of artifacts inherent in security analysis tools or distributions used in penetration testing or computer forensics.
Detection
| ID | DS0029 | Data source and component | Network Traffic: Network Traffic Content | Description | Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet). | 
|---|
Mitigation
| ID | M1042 | Name | Disable or Remove Feature or Program | Description | Remove or disable access to any systems, resources, and infrastructure that are not explicitly required to be available externally. | 
|---|
| ID | M1056 | Name | Pre-compromise | Description | This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on minimizing the amount and sensitivity of data available to external parties. | 
|---|