# T1595.002 Vulnerability Scanning

> As of 2026-10-05, T1595.002 (Vulnerability Scanning) appears in 207 tracked threats, first reported 2026-02-03 and most recently 2026-10-04, with linked actors including ShinyHunters, The Gentlemen, BonJoviGoesHard; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 207 (124 critical, 59 high, 19 medium)
- **First seen:** 2026-02-03
- **Last seen:** 2026-10-04
- **Threat actors:** 33
- **Detection rules:** 472 (counts only; Blue tier and above)

## Key facts

- **ID:** T1595.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Reconnaissance
- **Matrix:** Enterprise
- **Parent:** T1595
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1595/002/

## Activity timeline

T1595.002 first appeared in tracked threats on 2026-02-03 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 64 reports, and 207 of the 207 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1595.002 Vulnerability Scanning is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of [T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595). Threadlinqs maps 207 of 2623 tracked threats (7.9%) to it; by severity that is 124 critical, 59 high, 19 medium.

Threats that use T1595.002 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (185 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (85 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (81 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (80 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (76 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

33 tracked threat actors appear in the threats that use T1595.002; the most frequent are [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (4), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) (3), [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) (2), [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) (2), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (2).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1595.002.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Data sources

Telemetry that can reveal T1595.002, per MITRE ATT&CK.

- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 4
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [BonJoviGoesHard](https://intel.threadlinqs.com/actor/BonJoviGoesHard) — 2
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 2
- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 2
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 1
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 1

## Tracked threats

The 30 most recent of 207 tracked threats that use T1595.002.

- [CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2896) — high — 2026-10-04
- [TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…](https://intel.threadlinqs.com/threat/TL-2026-2889) — high — 2026-10-04
- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…](https://intel.threadlinqs.com/threat/TL-2026-2805) — critical — 2026-09-30
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)](https://intel.threadlinqs.com/threat/TL-2026-2698) — high — 2026-09-27
- [CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft](https://intel.threadlinqs.com/threat/TL-2026-2689) — high — 2026-09-27
- [Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)](https://intel.threadlinqs.com/threat/TL-2026-2682) — high — 2026-09-27
- [Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse Rows](https://intel.threadlinqs.com/threat/TL-2026-2675) — high — 2026-09-26
- [Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…](https://intel.threadlinqs.com/threat/TL-2026-2672) — high — 2026-09-26
- [ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Site](https://intel.threadlinqs.com/threat/TL-2026-2671) — critical — 2026-09-26
- [Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2670) — high — 2026-09-25
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [Autonomous AI Agent Operation (Strix, Cairn, Hermes) Steals 600K+ Payment Cards and Injects Skimmers into…](https://intel.threadlinqs.com/threat/TL-2026-2633) — critical — 2026-09-23
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red…](https://intel.threadlinqs.com/threat/TL-2026-2611) — critical — 2026-09-21
- [Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain](https://intel.threadlinqs.com/threat/TL-2026-2601) — high — 2026-09-21
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour…](https://intel.threadlinqs.com/threat/TL-2026-2584) — medium — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2574) — critical — 2026-09-19

## Related CVEs

CVEs referenced by the tracked threats that use T1595.002, most frequent first.

- [CVE-2026-60137](https://intel.threadlinqs.com/cve/CVE-2026-60137)
- [CVE-2026-63030](https://intel.threadlinqs.com/cve/CVE-2026-63030)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-9501](https://intel.threadlinqs.com/cve/CVE-2025-9501)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-61882](https://intel.threadlinqs.com/cve/CVE-2025-61882)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-35273](https://intel.threadlinqs.com/cve/CVE-2026-35273)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42208](https://intel.threadlinqs.com/cve/CVE-2026-42208)
- [CVE-2026-44748](https://intel.threadlinqs.com/cve/CVE-2026-44748)
- [CVE-2026-48939](https://intel.threadlinqs.com/cve/CVE-2026-48939)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)

## Detection coverage

Threadlinqs maintains 472 detection rules mapped to T1595.002 (SPL 170, KQL 137, Sigma 165). Rule content is available to Blue tier accounts and above; this page shows counts only.

472 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1595 Active Scanning](https://intel.threadlinqs.com/technique/T1595) — 340 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1595.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
