What is reconnaissance?
Reconnaissance attack is a method used by threat actors to gather information about target systems.
Azərbaycanca: Kəşfiyyat (reconnaissance) hücumu - təhlükə törədənlərin hədəf sistemlər haqqında məlumat toplamaq üçün istifadə etdikləri üsuldur.
How it works
Threat actors conduct reconnaissance to identify vulnerabilities, configurations, and potential entry points of target systems. This can be done through open-source intelligence, network scanning, or social engineering.
Defense checklist5
- 01
Monitor network traffic to detect suspicious activity
- 02
Strengthen access controls and implement MFA
- 03
Regularly update systems and software with the latest patches
- 04
Review and update security policies
- 05
Conduct security awareness training
Real-world evidence
In a case uncovered by Microsoft Incident Response, activity associated with Storm-2603 included reconnaissance targeting on-premises SharePoint servers, persistence through legitimate tools, and multiple remote access channels. Another threat actor used DLL sideloading and custom backdoors. Additionally, CISA warned of an active threat to Siemens PLCs, with threat actors conducting reconnaissance and capability development against U.S.-based Siemens PLC installations.
Sources
- A single intrusion exposed parallel activity from two unrelated threat actors operating at the same time, blending tactics, obscuring signals, and enabling sustained access while masking the full scope of the compromise. https://msft.it/6013vqXjW Microsoft Incident Response found activity associated with Storm-2603, including reconnaissance targeting on-premises SharePoint servers, persistence through legitimate tools, and multiple remote access channels. Investigators also uncovered a second threat actor whose use of DLL sideloading and custom backdoors complicated attribution and detection. The case highlights how overlapping intrusion activity can mask the full scope of an attack and why connected telemetry, coordinated response, and operational preparedness remain critical for defenders. Read the full cyberattack series report to learn more.x_msftsecintel
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructurehackernews
- How threat actors target critical infrar_cybersecurity
Other attack types
See also6
This guide is AI-written from the real incident sources skopnix collected — the examples above are drawn from those cited items, nothing is invented.