T1046: Network Service Discovery
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.CitationCISA AR21-126A FIVEHANDS May 2021
Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.
Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.Citationapple doco bonjour descriptionCitationmacOS APT Activity Bradley
Security context for executives and security teams
Network Service Discovery matters because it is often how an intruder turns initial access into an operational map: which hosts exist, which services are reachable, and which systems may be worth targeting next. For leaders, the key issue is not the scan itself, but whether the organization can distinguish approved administration and vulnerability management activity from unauthorized discovery across Windows, Linux, macOS, containers, IaaS, and network devices.
Executive priority
Prioritize this technique as a resilience and exposure-management control point. ATT&CK links it to many campaigns and groups, including espionage, financially motivated, ransomware, disruptive, and destructive activity, so coverage should not be limited to one threat model. Executives should ask whether segmentation, intrusion prevention, and removal of unnecessary services are evidenced in practice, especially between cloud and on-premises environments and around critical business systems.
Technical view
SOC, detection engineering, and IR teams should validate behavioral detection for unusual service enumeration across supported platforms rather than relying only on known tool names. ATT&CK provides no official detection text, but the related DET0376 detection strategy indicates this behavior is detectable as a cross-platform pattern. Validate visibility for port, vulnerability, wordlist-style scanning, cloud-to-cloud discovery, cloud-to-on-prem discovery, network-device probing, and macOS Bonjour/mDNS service discovery. Tune detections against expected asset-management, vulnerability-scanning, monitoring, and administrative activity to reduce false positives without suppressing suspicious new sources, unusual scan breadth, or discovery from non-administrative systems.
Likely telemetry
- Network flow metadata showing many destination hosts or ports contacted from one source
- Firewall, router, switch, and network device logs for allowed and denied connection attempts
- IDS/IPS alerts and boundary inspection logs related to service enumeration behavior
- Endpoint process execution and command-line telemetry where scanning utilities or service discovery tools are launched
- Cloud network telemetry such as virtual network flow logs and security group or access-control events
Detection direction
- Baseline approved vulnerability scanning, asset discovery, monitoring, and administrative sources before alerting on scan-like behavior.
- Look for service discovery originating from unusual user workstations, servers, containers, cloud workloads, or network segments that do not normally perform enumeration.
- Correlate discovery activity with preceding compromise indicators and following lateral movement or exploitation attempts rather than treating every scan as equally severe.
- Validate cloud and hybrid visibility, because ATT&CK notes discovery may occur among cloud hosts and across cloud-connected on-premises environments.
- Include macOS service discovery paths such as Bonjour/mDNS in environments where macOS systems are material.
Mitigation priorities
- Use Network Segmentation (M1030) to limit which systems can enumerate or reach sensitive services, especially across user, server, cloud, and critical infrastructure zones.
- Use Network Intrusion Prevention (M1031) and IDS/IPS signatures at relevant boundaries to block or alert on suspicious enumeration traffic where practical.
- Disable or Remove Feature or Program (M1042) by reducing unnecessary services and exposed features so discovery yields fewer usable targets.
- Maintain service inventory and ownership so defenders can quickly decide whether discovered services are expected, unauthorized, or vulnerable.
- Review segmentation and service exposure as part of incident response readiness and compliance evidence, not only as an architecture exercise.
Additional notes and limits
The relationship set shows broad use of T1046 across multiple named campaigns and groups, which supports treating the behavior as a common discovery pattern rather than a niche indicator. The supplied mitigations map cleanly to exposure reduction, traffic control, and service minimization. Detection should be environment-specific because legitimate scanning and administration can look similar to adversary discovery.
MITRE did not provide official detection text for this object in the supplied fields. The assessment cannot assert current exploitation, customer exposure, or guaranteed detection coverage. Local network architecture, cloud connectivity, approved scanner inventory, endpoint telemetry, and logging retention are required to judge actual risk and control effectiveness.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Network Service Discovery
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.CitationCISA AR21-126A FIVEHANDS May 2021
Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.
Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.Citationapple doco bonjour descriptionCitationmacOS APT Activity Bradley
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
