M ManySignal
TA0007 ATT&CK Tactic

Discovery

After gaining access, adversaries enumerate accounts, permissions, services, and resources to identify lateral movement paths and valuable data. Discovery is a critical pre-attack reconnaissance phase — detecting it early disrupts attack planning before damage occurs.

Coverage

Techniques covered
31
Cloud enumeration rules
18
Identity discovery rules
12

Threat context

How adversaries enumerate your environment

Discovery is the reconnaissance phase that follows initial access. Before moving laterally or escalating privileges, adversaries map their target: what accounts exist, what permissions do they have, what services are running, and where is sensitive data stored. In cloud environments, this reconnaissance is performed through the same APIs legitimate administrators use — making it appear benign without behavioural context.

ManySignal detects discovery through behavioural baselining: a developer who normally calls EC2 and S3 APIs should not be calling IAM, GuardDuty, Config, and CloudTrail describe APIs in rapid succession. That pattern — broad, multi-service enumeration by an unusual principal — is a high-confidence discovery signal regardless of individual API call legitimacy.

Discovery: frequently asked questions

What is ATT&CK Discovery (TA0007)?

Discovery techniques allow adversaries to understand the environment they have compromised. After gaining access, attackers enumerate accounts, permissions, resources, and network topology to plan lateral movement, privilege escalation, and data exfiltration paths.

Why is cloud service discovery particularly dangerous?

In cloud environments, discovery can be performed with a small number of API calls that return comprehensive information about the entire environment. A single describe-instances call reveals all EC2 resources; list-users reveals all IAM users. This makes cloud discovery much faster and broader than traditional network scanning.

How does ManySignal detect discovery activity without endpoint access?

In cloud environments, all discovery API calls appear in CloudTrail. ManySignal baselines normal list/describe call patterns per IAM principal. An unusual spike in read-only enumeration calls — especially across services or accounts the principal doesn't normally access — triggers a discovery alert.

Catch reconnaissance activity before attackers identify their targets

ManySignal's behavioural baselines detect post-compromise enumeration within minutes — disrupting attack planning before lateral movement begins.