Threadlinqs IntelligenceStart free

ATT&CK techniqueDiscovery

T1046 Network Service Discovery

DiscoveryEnterprise

As of 2026-10-05, T1046 (Network Service Discovery) appears in 374 tracked threats, first reported 2025-10-13 and most recently 2026-10-03, with linked actors including Static Tundra, The Gentlemen, Cavern Manticore; it most often appears alongside T1190 (Exploit Public-Facing Application).

Tracked threats
374192 critical, 145 high, 30 medium
First seen
2025-10-13
Last seen
2026-10-03
Threat actors
85In the threats using it
Detection rules
354Blue tier and above

Data as of:

Activity timeline

T1046 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 145 reports, and 373 of the 374 threats were reported in the twelve months to 2026-10.

How adversaries use it

T1046 Network Service Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 374 of 2623 tracked threats (14.3%) to it; by severity that is 192 critical, 145 high, 30 medium.

Threats that use T1046 most often also use T1190 Exploit Public-Facing Application (304 threats), T1059 Command and Scripting Interpreter (230 threats), T1005 Data from Local System (195 threats), T1078 Valid Accounts (180 threats), T1071 Application Layer Protocol (179 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

85 tracked threat actors appear in the threats that use T1046; the most frequent are Static Tundra (8), The Gentlemen (6), Cavern Manticore (5), DragonForce (5), FSB Center 16 (5).

Mitigations

MITRE ATT&CK lists 3 mitigations for T1046.

Data sources

Telemetry that can reveal T1046, per MITRE ATT&CK.

  • Cloud Service — Cloud Service Enumeration
  • Command — Command Execution
  • Network Traffic — Network Traffic Flow

Threat actors using it

Tracked threats

The 30 most recent of 374 tracked threats that use T1046.

Detection coverage

Threadlinqs maintains 354 detection rules mapped to T1046 (SPL 112, KQL 113, Sigma 129). Rule content is available to Blue tier accounts and above; this page shows counts only.

354 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans