What it is
everything an attacker does to learn about a target before touching it. That includes active scanning of public-facing systems, and passive collection that never touches the target at all: pulling employee names and roles from LinkedIn, reading job postings for a hint at the tech stack, checking DNS and certificate records, searching breach dumps for reused credentials, browsing the company's own public website for org charts and vendor names.
Why it isn't covered here
every range on this platform is built from a network already compromised, captured as the attacker left it. Recon happens before that point, and it happens on infrastructure the attacker controls, not the victim's. There's no telemetry a captured range could ever contain for it, because the activity never touches anything a defender's sensors can see. This isn't a gap in coverage; it's a property of what a network's own logs can and can't record.
Where the visibility actually comes from, in a real SOC
mostly not your own logs. Passive DNS and certificate-transparency logs can show a domain being prepared. Threat intelligence feeds sometimes report scanning activity against your public IP ranges. Web server and perimeter logs catch active scanning if it's aggressive enough to be noisy. But most reconnaissance, especially the passive kind, leaves the victim with nothing to hunt at all. Awareness of the tactic matters more than detection technique here.
The techniques below are indexed for reference so the matrix stays complete. They are not pending write-ups.
- T1589 Gather Victim Identity Information (index only)
- T1589.001 Credentials (index only)
- T1589.002 Email Addresses (index only)
- T1589.003 Employee Names (index only)
- T1590 Gather Victim Network Information (index only)
- T1590.001 Domain Properties (index only)
- T1590.002 DNS (index only)
- T1590.003 Network Trust Dependencies (index only)
- T1590.004 Network Topology (index only)
- T1590.005 IP Addresses (index only)
- T1590.006 Network Security Appliances (index only)
- T1591 Gather Victim Org Information (index only)
- T1591.001 Determine Physical Locations (index only)
- T1591.002 Business Relationships (index only)
- T1591.003 Identify Business Tempo (index only)
- T1591.004 Identify Roles (index only)
- T1592 Gather Victim Host Information (index only)
- T1592.001 Hardware (index only)
- T1592.002 Software (index only)
- T1592.003 Firmware (index only)
- T1592.004 Client Configurations (index only)
- T1593 Search Open Websites/Domains (index only)
- T1593.001 Social Media (index only)
- T1593.002 Search Engines (index only)
- T1593.003 Code Repositories (index only)
- T1594 Search Victim-Owned Websites (index only)
- T1595 Active Scanning (index only)
- T1595.001 Scanning IP Blocks (index only)
- T1595.002 Vulnerability Scanning (index only)
- T1595.003 Wordlist Scanning (index only)
- T1596 Search Open Technical Databases (index only)
- T1596.001 DNS/Passive DNS (index only)
- T1596.002 WHOIS (index only)
- T1596.003 Digital Certificates (index only)
- T1596.004 CDNs (index only)
- T1596.005 Scan Databases (index only)
- T1597 Search Closed Sources (index only)
- T1597.001 Threat Intel Vendors (index only)
- T1597.002 Purchase Technical Data (index only)
- T1598 Phishing for Information (index only)
- T1598.001 Spearphishing Service (index only)
- T1598.002 Spearphishing Attachment (index only)
- T1598.003 Spearphishing Link (index only)
- T1598.004 Spearphishing Voice (index only)
- T1681 Search Threat Vendor Data (index only)
- T1682 Query Public AI Services (index only)