risk
Adversary reconnaissance and information gathering
Because adversaries scan perimeters, sniff exposed networks, mine open-source and public information, and surveil personnel and processes, they build a detailed map of the IT environment and its weaknesses, resulting in better-targeted, more likely-to-succeed follow-on attacks.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Logging, Monitoring & Detection
- Network & Communications Security
- taxonomy
- nist-800-30-threat-event
- inherent_rating
- medium
Details
- risk_id
- cyber-reconnaissance
- category
- cyber_security
- likelihood
- very_high
- impact
- low
- inherent_rating
- medium
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-LOG-11 — Monitor external sources for unauthorized information disclosure mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Detecting and removing improperly disclosed information reduces the open-source attack surface adversaries mine during reconnaissance.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Threat-intel-enriched correlation flags distributed scanning and traffic to known reconnaissance infrastructure.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Deny-by-default boundary reduces externally reachable/scannable services, shrinking the attack surface adversaries map.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Perimeter monitoring detects active scanning/probing, catching the reconnaissance subset that generates observable network activity.
- UC-NET-11 — Conceal operational information from adversaries mitigates Adversary reconnaissance and information gathering
- strength
- primary
- rationale
- OPSEC denial of adversary collection plus concealment/misdirection and randomized observables directly defeat reconnaissance and information gathering.
- UC-NET-10 — Deploy deception and dynamic detection capabilities mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Decoy components attract and detect scanning and probing, revealing reconnaissance activity.
- UC-BCDR-13 — Operate continuous security protection services mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Network/perimeter protection limits the scanning and probing adversaries use to map the environment.
- UC-NET-12 — Restrict communication-capable devices, ports, and sensors mitigates Adversary reconnaissance and information gathering
- strength
- related
- rationale
- Prohibiting remote activation of cameras/microphones and restricting sensor data denies an adversary a surveillance/collection channel.