Loading the current evidence view. Navigation and account controls remain available.
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
Tactics: reconnaissance
2
known groups
0
software
0
corpus matches
about
Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with their target industries, capabilities/objectives, or other operational concerns. These reports may include descriptions of behavior, detailed breakdowns of attacks, atomic indicators such as malware hashes or IP addresses, timelines of a group’s activity, and more. Adversaries may change their behavior when planning their future operations.
Adversaries have been observed replacing atomic indicators mentioned in blog posts in under a week. Adversaries have also been seen searching for their own domain names in threat vendor data and then taking them down, likely to avoid seizure or further investigation.
This technique is distinct from Threat Intel Vendors in that it describes threat actors performing reconnaissance on their own activity, not in search of victim information.
used by actors
2 known groups
software
0 malware & tools implement this
None mapped.
corpus indicators tagged T1681
0 carry this technique
A shared-technique signal for hunting: each row resolves to its own verdict. Not attribution to any one group.
No corpus indicators are tagged with this technique yet.