# T1046 Network Service Discovery

> As of 2026-10-05, T1046 (Network Service Discovery) appears in 374 tracked threats, first reported 2025-10-13 and most recently 2026-10-03, with linked actors including Static Tundra, The Gentlemen, Cavern Manticore; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 374 (192 critical, 145 high, 30 medium)
- **First seen:** 2025-10-13
- **Last seen:** 2026-10-03
- **Threat actors:** 85
- **Detection rules:** 354 (counts only; Blue tier and above)

## Key facts

- **ID:** T1046
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1046/

## Activity timeline

T1046 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 145 reports, and 373 of the 374 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1046 Network Service Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 374 of 2623 tracked threats (14.3%) to it; by severity that is 192 critical, 145 high, 30 medium.

Threats that use T1046 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (304 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (230 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (195 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (180 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (179 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

85 tracked threat actors appear in the threats that use T1046; the most frequent are [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (8), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (6), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (5), [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) (5), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) (5).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1046.

- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1046, per MITRE ATT&CK.

- Cloud Service — Cloud Service Enumeration
- Command — Command Execution
- Network Traffic — Network Traffic Flow

## Threat actors using it

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 8
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 6
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 5
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 5
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 5
- [Everest](https://intel.threadlinqs.com/actor/Everest) — 4
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 4
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 4
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 4
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 3
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 3
- [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom) — 3

## Tracked threats

The 30 most recent of 374 tracked threats that use T1046.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — high — 2026-10-03
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2693) — critical — 2026-09-27
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the…](https://intel.threadlinqs.com/threat/TL-2026-2639) — high — 2026-09-24
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root](https://intel.threadlinqs.com/threat/TL-2026-2557) — critical — 2026-09-18
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via…](https://intel.threadlinqs.com/threat/TL-2026-2489) — critical — 2026-09-13
- [Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…](https://intel.threadlinqs.com/threat/TL-2026-2463) — critical — 2026-09-12
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…](https://intel.threadlinqs.com/threat/TL-2026-2396) — critical — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [CVE-2026-75754: Unauthenticated Remote Root in ASUS Control Center Enterprise (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2354) — critical — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Frontier AI Agents Compress Full Enterprise Intrusion Chain into Under 10 Hours (Unit 42 Investigation)](https://intel.threadlinqs.com/threat/TL-2026-2341) — high — 2026-09-05
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- ["Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay](https://intel.threadlinqs.com/threat/TL-2026-2276) — high — 2026-09-01

## Related CVEs

CVEs referenced by the tracked threats that use T1046, most frequent first.

- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)
- [CVE-2017-17215](https://intel.threadlinqs.com/cve/CVE-2017-17215)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)

## Detection coverage

Threadlinqs maintains 354 detection rules mapped to T1046 (SPL 112, KQL 113, Sigma 129). Rule content is available to Blue tier accounts and above; this page shows counts only.

354 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1046
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
