Reconnaissance
Reconnaissance occurs before Initial Access — adversaries map your attack surface, collect employee information, and identify exploitable weaknesses. Correlating reconnaissance signals with subsequent attack attempts enables early warning before the first credential is tested.
Coverage
- Techniques covered
- 10
- WAF-based rules
- 8
- Phishing signal rules
- 6
Threat context
How adversaries gather pre-attack intelligence
Targeted attacks begin with extensive reconnaissance. Adversaries use Shodan, FOFA, and Censys to map internet-exposed services; LinkedIn and email harvesting tools to collect employee identities; and vulnerability databases to identify which software versions are exploitable. This intelligence gathering often happens weeks before the first intrusion attempt.
ManySignal's contribution to reconnaissance detection is correlation: when the same IP or infrastructure that was scanning your WAF later attempts authentication against Okta, those two events are linked in the investigation timeline. This cross-event correlation turns isolated low-priority WAF alerts into high-value early warning signals.
Reconnaissance techniques ManySignal surfaces
Active Scanning
Port scanning, vulnerability scanning, and web crawling targeting your infrastructure.
Phishing for Information
Pretexting calls, emails, and messages designed to extract credentials or information.
Gather Victim Identity Information
Collecting employee email addresses, usernames, and organisational charts from OSINT.
Gather Victim Network Information
Mapping IP ranges, ASNs, and exposed services through public sources.
Reconnaissance: frequently asked questions
What is ATT&CK Reconnaissance (TA0043)?
Reconnaissance is the pre-attack phase where adversaries gather information about the target. Unlike most ATT&CK tactics, reconnaissance happens before the adversary has any access to your environment — making prevention and early warning more important than detection.
Can ManySignal detect reconnaissance that happens externally?
ManySignal can detect active scanning from WAF and network logs, and phishing-for-information attempts from email security logs. True OSINT reconnaissance (searching LinkedIn, Shodan, etc.) happens entirely externally and cannot be detected through internal telemetry.
How do I use ManySignal to monitor my attack surface for reconnaissance targets?
Enable the EASM-style attack surface visibility through ManySignal's Cloudflare, AWS, and network integrations. ManySignal aggregates scanning activity from WAF logs and correlates repeated probes from the same infrastructure with subsequent authentication or exploitation attempts.
Connect pre-attack scanning to authentication attempts
ManySignal correlates WAF scanning activity with subsequent authentication and exploitation attempts for early attack warning.