LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1046: Network Service Discovery

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.CitationCISA AR21-126A FIVEHANDS May 2021

Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.

Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.Citationapple doco bonjour descriptionCitationmacOS APT Activity Bradley

EnterpriseT1046TechniqueObject v3.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Network Service Discovery matters because it is often how an intruder turns initial access into an operational map: which hosts exist, which services are reachable, and which systems may be worth targeting next. For leaders, the key issue is not the scan itself, but whether the organization can distinguish approved administration and vulnerability management activity from unauthorized discovery across Windows, Linux, macOS, containers, IaaS, and network devices.

Executive priority

Prioritize this technique as a resilience and exposure-management control point. ATT&CK links it to many campaigns and groups, including espionage, financially motivated, ransomware, disruptive, and destructive activity, so coverage should not be limited to one threat model. Executives should ask whether segmentation, intrusion prevention, and removal of unnecessary services are evidenced in practice, especially between cloud and on-premises environments and around critical business systems.

Technical view

SOC, detection engineering, and IR teams should validate behavioral detection for unusual service enumeration across supported platforms rather than relying only on known tool names. ATT&CK provides no official detection text, but the related DET0376 detection strategy indicates this behavior is detectable as a cross-platform pattern. Validate visibility for port, vulnerability, wordlist-style scanning, cloud-to-cloud discovery, cloud-to-on-prem discovery, network-device probing, and macOS Bonjour/mDNS service discovery. Tune detections against expected asset-management, vulnerability-scanning, monitoring, and administrative activity to reduce false positives without suppressing suspicious new sources, unusual scan breadth, or discovery from non-administrative systems.

Likely telemetry

  • Network flow metadata showing many destination hosts or ports contacted from one source
  • Firewall, router, switch, and network device logs for allowed and denied connection attempts
  • IDS/IPS alerts and boundary inspection logs related to service enumeration behavior
  • Endpoint process execution and command-line telemetry where scanning utilities or service discovery tools are launched
  • Cloud network telemetry such as virtual network flow logs and security group or access-control events

Detection direction

  • Baseline approved vulnerability scanning, asset discovery, monitoring, and administrative sources before alerting on scan-like behavior.
  • Look for service discovery originating from unusual user workstations, servers, containers, cloud workloads, or network segments that do not normally perform enumeration.
  • Correlate discovery activity with preceding compromise indicators and following lateral movement or exploitation attempts rather than treating every scan as equally severe.
  • Validate cloud and hybrid visibility, because ATT&CK notes discovery may occur among cloud hosts and across cloud-connected on-premises environments.
  • Include macOS service discovery paths such as Bonjour/mDNS in environments where macOS systems are material.

Mitigation priorities

  • Use Network Segmentation (M1030) to limit which systems can enumerate or reach sensitive services, especially across user, server, cloud, and critical infrastructure zones.
  • Use Network Intrusion Prevention (M1031) and IDS/IPS signatures at relevant boundaries to block or alert on suspicious enumeration traffic where practical.
  • Disable or Remove Feature or Program (M1042) by reducing unnecessary services and exposed features so discovery yields fewer usable targets.
  • Maintain service inventory and ownership so defenders can quickly decide whether discovered services are expected, unauthorized, or vulnerable.
  • Review segmentation and service exposure as part of incident response readiness and compliance evidence, not only as an architecture exercise.
Additional notes and limits

The relationship set shows broad use of T1046 across multiple named campaigns and groups, which supports treating the behavior as a common discovery pattern rather than a niche indicator. The supplied mitigations map cleanly to exposure reduction, traffic control, and service minimization. Detection should be environment-specific because legitimate scanning and administration can look similar to adversary discovery.

MITRE did not provide official detection text for this object in the supplied fields. The assessment cannot assert current exploitation, customer exposure, or guaranteed detection coverage. Local network architecture, cloud connectivity, approved scanner inventory, endpoint telemetry, and logging retention are required to judge actual risk and control effectiveness.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Network Service Discovery

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.CitationCISA AR21-126A FIVEHANDS May 2021

Within cloud environments, adversaries may attempt to discover services running on other cloud hosts. Additionally, if the cloud environment is connected to a on-premises environment, adversaries may be able to identify services running on non-cloud systems as well.

Within macOS environments, adversaries may use the native Bonjour application to discover services running on other macOS hosts within a network. The Bonjour mDNSResponder daemon automatically registers and advertises a host’s registered services on the network. For example, adversaries can use a mDNS query (such as dns-sd -B _ssh._tcp .) to find other systems broadcasting the ssh service.Citationapple doco bonjour descriptionCitationmacOS APT Activity Bradley

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
3.2
Created
Modified
Raw hash
6aef88d1fc6fbbfb...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.