Activity timeline
T1596 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 44 reports, and 95 of the 95 threats were reported in the twelve months to 2026-08.
How adversaries use it
T1596 Search Open Technical Databases is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix. Threadlinqs maps 95 of 2623 tracked threats (3.6%) to it; by severity that is 33 critical, 37 high, 18 medium, 1 low.
Threats that use T1596 most often also use T1190 Exploit Public-Facing Application (67 threats), T1059 Command and Scripting Interpreter (51 threats), T1005 Data from Local System (50 threats), T1552 Unsecured Credentials (49 threats), T1078 Valid Accounts (47 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
26 tracked threat actors appear in the threats that use T1596; the most frequent are ShinyHunters (4), Scattered LAPSUS$ Hunters (3), Scattered Spider (3), The Com (3), UNC6040 (3).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1596.
Threat actors using it
Tracked threats
The 30 most recent of 95 tracked threats that use T1596.
- AI-Generated Exploit Scripts Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurehigh
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructurecritical
- Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theftcritical
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolencritical
- Google AI Agents (Big Sleep, CodeMender, Gemini) Fix 1,072 Chrome Security Bugs Across Chrome 149/150…
- ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades…medium
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claimshigh
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groupsmedium
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026high
- KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Carshigh
- Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US…high
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggeringcritical
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action…medium
- Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances…medium
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production…high
- Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive…medium
- Executive Order: Defense Contractors Ordered to Map Software Suppliers Across Critical Supply Chains…
- Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime…medium
- Patriot Bait Actor "bandcampro" Abuses Jailbroken Google Gemini CLI to Build and Operate a Dental Clinic…medium
- Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)critical
- OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)medium
- Iran-Linked Actors Track US Military Personnel via SS7 Roaming Abuse and Ad-Tech Location Datahigh
- NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for…high
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)critical
- Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military…high
- CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK…critical
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659…critical
- CVE-2026-3985: Blind SQL Injection in Creative Mail WordPress Plugin, Discovered by Fully Automated AI…high
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaignhigh
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1596 (SPL 15, KQL 10, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1596.001 DNS/Passive DNS — 2 tracked threats
- T1596.002 WHOIS — 0 tracked threats
- T1596.003 Digital Certificates — 2 tracked threats
- T1596.004 CDNs — 0 tracked threats
- T1596.005 Scan Databases — 26 tracked threats