# T1592.004 Client Configurations

> As of 2026-10-05, T1592.004 (Client Configurations) appears in 17 tracked threats, first reported 2026-06-09 and most recently 2026-08-25, with linked actors including Storm-2755; it most often appears alongside T1588.006 (Vulnerabilities).

- **Tracked threats:** 17 (5 critical, 10 high, 2 medium)
- **First seen:** 2026-06-09
- **Last seen:** 2026-08-25
- **Threat actors:** 1
- **Detection rules:** 18 (counts only; Blue tier and above)

## Key facts

- **ID:** T1592.004
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1592
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1592/004/

## Activity timeline

T1592.004 first appeared in tracked threats on 2026-06-09 and was most recently reported on 2026-08-25. The busiest month was 2026-07 with 8 reports, and 17 of the 17 threats were reported in the twelve months to 2026-08.

## How adversaries use it

T1592.004 Client Configurations is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1592 Gather Victim Host Information](https://intel.threadlinqs.com/technique/T1592). Threadlinqs maps 17 of 2623 tracked threats (0.6%) to it; by severity that is 5 critical, 10 high, 2 medium.

Threats that use T1592.004 most often also use [T1588.006 Vulnerabilities](https://intel.threadlinqs.com/technique/T1588.006) (10 threats), [T1119 Automated Collection](https://intel.threadlinqs.com/technique/T1119) (8 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (7 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (7 threats), [T1587.004 Exploits](https://intel.threadlinqs.com/technique/T1587.004) (7 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

1 tracked threat actor appear in the threats that use T1592.004; the most frequent are [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1592.004.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1592.004, per MITRE ATT&CK.

- Internet Scan — Response Content

## Threat actors using it

- [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755) — 1

## Tracked threats

17 tracked threats use T1592.004.

- [AMD Ionic Cloud Driver Vulnerabilities Affecting VMware ESX (CVE-2025-62623, CVE-2025-62624, CVE-2025-62627)](https://intel.threadlinqs.com/threat/TL-2026-2146) — high — 2026-08-25
- [Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…](https://intel.threadlinqs.com/threat/TL-2026-1993) — high — 2026-08-12
- [Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance…](https://intel.threadlinqs.com/threat/TL-2026-1930) — high — 2026-08-07
- [TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUs](https://intel.threadlinqs.com/threat/TL-2026-1954) — high — 2026-08-06
- [Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1835) — critical — 2026-08-03
- [Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses](https://intel.threadlinqs.com/threat/TL-2026-1829) — critical — 2026-08-03
- [COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft](https://intel.threadlinqs.com/threat/TL-2026-1822) — critical — 2026-08-02
- [Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files](https://intel.threadlinqs.com/threat/TL-2026-1817) — high — 2026-08-02
- [KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization](https://intel.threadlinqs.com/threat/TL-2026-1701) — high — 2026-07-25
- [Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow…](https://intel.threadlinqs.com/threat/TL-2026-1690) — high — 2026-07-23
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and…](https://intel.threadlinqs.com/threat/TL-2026-1475) — high — 2026-07-18
- [Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…](https://intel.threadlinqs.com/threat/TL-2026-1403) — critical — 2026-07-16
- [Operation Fake KickOff — Attackers Abuse Recruiters and SaaS to Harvest Corporate Google Workspace Credentials](https://intel.threadlinqs.com/threat/TL-2026-2395) — high — 2026-07-15
- ['Ill Bloom' Weak-Randomness Vulnerability in Legacy Crypto Wallets Actively Exploited to Drain $3.1M+](https://intel.threadlinqs.com/threat/TL-2026-1170) — critical — 2026-07-10
- [Alibaba to Ban Claude Code Over Alleged Embedded Network-Fingerprinting Mechanism](https://intel.threadlinqs.com/threat/TL-2026-1096) — medium — 2026-07-03
- [CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google Chrome](https://intel.threadlinqs.com/threat/TL-2026-0740) — high — 2026-06-09

## Related CVEs

CVEs referenced by the tracked threats that use T1592.004, most frequent first.

- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2026-15718](https://intel.threadlinqs.com/cve/CVE-2026-15718)
- [CVE-2026-15719](https://intel.threadlinqs.com/cve/CVE-2026-15719)
- [CVE-2026-15764](https://intel.threadlinqs.com/cve/CVE-2026-15764)
- [CVE-2026-15765](https://intel.threadlinqs.com/cve/CVE-2026-15765)
- [CVE-2026-20349](https://intel.threadlinqs.com/cve/CVE-2026-20349)
- [CVE-2026-25589](https://intel.threadlinqs.com/cve/CVE-2026-25589)
- [CVE-2026-48318](https://intel.threadlinqs.com/cve/CVE-2026-48318)

## Detection coverage

Threadlinqs maintains 18 detection rules mapped to T1592.004 (SPL 6, KQL 6, Sigma 6). Rule content is available to Blue tier accounts and above; this page shows counts only.

18 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1592 Gather Victim Host Information](https://intel.threadlinqs.com/technique/T1592) — 153 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1592.004
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
