MITRE ATT&CK Technique
T1595.002Vulnerability Scanning
- First Reported
- Sep 26, 2026
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
These scans may also include more broad attempts to [Gather Victim Host Information](https://attack.mitre.org/techniques/T1592) that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts.(Citation: OWASP Vuln Scanning) Information from these scans may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Search Open Technical Databases](https://attack.mitre.org/techniques/T1596)), establishing operational resources (ex: [Develop Capabilities](https://attack.mitre.org/techniques/T1587) or [Obtain Capabilities](https://attack.mitre.org/techniques/T1588)), and/or initial access (ex: [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).
These scans may also include more broad attempts to [Gather Victim Host Information](https://attack.mitre.org/techniques/T1592) that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts.(Citation: OWASP Vuln Scanning) Information from these scans may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Search Open Technical Databases](https://attack.mitre.org/techniques/T1596)), establishing operational resources (ex: [Develop Capabilities](https://attack.mitre.org/techniques/T1587) or [Obtain Capabilities](https://attack.mitre.org/techniques/T1588)), and/or initial access (ex: [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190)).
- Tactics
- Reconnaissance
- Platforms
- PRE
- Parent Technique
- T1595 · Active Scanning
- MITRE Version
- 1.0
- Last Modified
- May 12, 2026
Reported Context (3)
- wp2s_poll.py probed WordPress sites and REST batch-route behavior, classified targets, and retried requests using multipart encoding after JSON requests returned HTTP 403. TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials
- Agents probed government websites for vulnerabilities, including SQL injection and input-handling tests. AI Agents Tried SQL Injection and Other Probes Against U.S. and Canadian Government Websites
- Repeated POST requests to the PSEMHUB hub servlet checked whether targeted servers were exploitable. ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273
CVE (3)
Malware (1)
Threat Actors (2)
MITRE ATT&CK (12)
Vendors (3)
Products (7)
Tools (8)
Industries (1)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.