Activity timeline
T1592.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 8 reports, and 17 of the 17 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1592.004 Client Configurations is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1592 Gather Victim Host Information. Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 10 high, 2 medium.
Threats that use T1592.004 most often also use T1588.006 Vulnerabilities (10 threats), T1119 Automated Collection (8 threats), T1005 Data from Local System (7 threats), T1082 System Information Discovery (7 threats), T1587.004 Exploits (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
1 tracked threat actor appear in the threats that use T1592.004; the most frequent are Storm-2755 (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1592.004.
Data sources
Telemetry that can reveal T1592.004, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
17 tracked threats use T1592.004.
- AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)high
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…high
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…high
- TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUshigh
- Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theftcritical
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addressescritical
- COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theftcritical
- Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Fileshigh
- KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilizationhigh
- Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow…high
- OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerabilitymedium
- SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…high
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentialshigh
- 'Ill Bloom' Weak-Randomness Vulnerability in Legacy Crypto Wallets Actively Exploited to Drain $3.1M+critical
- Alibaba to Ban Claude Code Over Alleged Embedded Network-Fingerprinting Mechanismmedium
- CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google Chromehigh
Detection coverage
Threadlinqs maintains 18 detection rules mapped to T1592.004 (SPL 6, KQL 6, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1592 Gather Victim Host Information — 153 tracked threats at the technique level.