[ATT&CK Series] T1589 - Gather Victim Identity Information
How adversaries collect usernames, email addresses, and names to build targets for phishing and credential stuffing.
How adversaries collect usernames, email addresses, and names to build targets for phishing and credential stuffing.
How attackers map perimeter infrastructure, DNS records, and network topology to identify entry points.
How adversaries research organizational structures, physical locations, and business relationships to tailor their attacks.
How adversaries collect technical details about hardware, software, and firmware to identify exploitable vulnerabilities.
How adversaries leverage social media, search engines, and code repositories to gather intelligence without direct contact.
How adversaries scrape and browse a target organization's own website to find hidden directories and operational clues.
A deep dive into MITRE ATT&CK Technique T1595 (Active Scanning), exploring how attackers probe networks to map out hosts and vulnerabilities.
How adversaries query WHOIS, DNS, CT logs, and scan databases to map an organization's attack surface passively.
How adversaries purchase credentials and threat intelligence from dark web markets and closed forums.
How adversaries use deceptive communication to harvest credentials and organizational details without delivering malware.
How adversaries monitor public threat reporting to track their own exposure and rotate infrastructure.
How adversaries use LLMs to synthesize and scale open-source intelligence gathering.