T1595.003sub-technique of T1595 Active Scanning

Wordlist Scanning

PREnothing on this site yetT1595.003 on attack.mitre.org

Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal is the identification of content and infrastructure rather than the discovery of valid credentials. Wordlists used in these scans may contain generic, commonly used names and file extensions or terms specific to a particular software.

MITRE ATT&CK 19.2, retrieved 2026-09-12

how MITRE says to see it

Detection of Wordlist Scanning

  • Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet).

what reduces it

  • M1056 Pre-compromise. This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on minimizing the amount and sensitivity of data available to external parties.
  • M1042 Disable or Remove Feature or Program. Remove or disable access to any systems, resources, and infrastructure that are not explicitly required to be available externally.

the rest of T1595

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.