Skip to main content

Core / Ccc / Threats / DEV

Automated Enumeration and Reconnaissance by Non-human Entities

CCC.Core.TH15

Automated processes may be used to gather details about service and child resource elements such as APIs, file systems, or directories. This information can reveal vulnerabilities, misconfigurations, and the network topology, which can be used to plan an attack against the system, the service, or its child resources.

Related Capabilities

IDTitleDescription
CCC.Core.CP14API AccessThe service exposes a port enabling external actors to interact programmatically with the service and its resources using HTTP protocol methods such as GET, POST, PUT, and DELETE.

Related Controls

IDTitleDescription
CCC.Core.CN07Alert on Unusual Enumeration ActivityEnsure that logs and associated alerts are generated when unusual enumeration activity is detected that may indicate reconnaissance activities.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1580Cloud Infrastructure Discovery