How to Defeat MITRE ATT&CK Reconnaissance Techniques
MITRE ATT&CK Reconnaissance (TA0043) techniques section maps out how threat actors gather information about potential targets.
Like other ATT&CK tactics (like initial access and lateral movement), reconnaissance provides useful threat intelligence on adversary tactics, techniques, and procedures (TTPs). It is a realistic approximation of what will happen if you become a target.
Most attack chains will involve one or more techniques outlined before initial access. In one review of recently reported manufacturing cyber attacks reported by PwC, 24% of attacks started with reconnaissance activity and were then followed by hacking or system penetration. The remainder almost certainly did, too, but the reconnaissance was too stealthy to be noticed during remediation.
Technical security controls can’t prevent all MITRE ATT&CK reconnaissance techniques. But they can mitigate the risk of some of them effectively.
This blog reviews MITRE ATT&CK reconnaissance techniques and shows how SenseOn can help you detect and respond to some of them.