MITRE ATT&CK Technique
T1595Active Scanning
- First Reported
- Sep 13, 2026
- Latest Reported
- Sep 27, 2026
Official Description
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.
Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP.(Citation: Botnet Scan)(Citation: OWASP Fingerprinting) Information from these scans may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Search Open Technical Databases](https://attack.mitre.org/techniques/T1596)), establishing operational resources (ex: [Develop Capabilities](https://attack.mitre.org/techniques/T1587) or [Obtain Capabilities](https://attack.mitre.org/techniques/T1588)), and/or initial access (ex: [External Remote Services](https://attack.mitre.org/techniques/T1133) or [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).
Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP.(Citation: Botnet Scan)(Citation: OWASP Fingerprinting) Information from these scans may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Search Open Technical Databases](https://attack.mitre.org/techniques/T1596)), establishing operational resources (ex: [Develop Capabilities](https://attack.mitre.org/techniques/T1587) or [Obtain Capabilities](https://attack.mitre.org/techniques/T1588)), and/or initial access (ex: [External Remote Services](https://attack.mitre.org/techniques/T1133) or [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).
- Tactics
- Reconnaissance
- Platforms
- PRE
- MITRE Version
- 1.0
- Last Modified
- Oct 24, 2025
Sub-techniques (3)
Reported Context (2)
- The scanner checked remote targets for exposed WordPress installation and configuration pages to identify further attack targets. Attackers Exploit Telerik CVE-2019-18935 to Install Web Shells and Scan for Exposed WordPress Pages
- The actor scanned 1,386 Gitea instances and probed for open registration before prioritizing targets. Red Heron Exploits Gitea CVE-2026-60004 in Multinational Campaign, Deploys Linux Rootkit
CVE (2)
Malware (3)
Threat Actors (2)
MITRE ATT&CK (17)
Vendors (2)
Products (10)
Tools (7)
Industries (11)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.