Reconnaissance
What is Reconnaissance?
The initial phase of a cyberattack where threat actors gather information about target systems, networks, and organizations to plan their attack strategy.
Terms that appear alongside reconnaissance
Each of these is named in at least one of the same controls as reconnaissance. The number is how many controls name both.
- lateral movement 3 shared controls
- attack surface 2 shared controls
- chain of custody 2 shared controls
- purple team 2 shared controls
- privilege escalation 2 shared controls
- mitre 2 shared controls
- red team 2 shared controls
- blue team 2 shared controls
Frameworks that govern reconnaissance
What the standards actually require on reconnaissance
Requirements naming reconnaissance across 6 standards, quoted from the control text.
Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations.
MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact · MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact →Active reconnaissance including port scans, service identification, and banner grabbing must enumerate live hosts and exposed services within the agreed scope.
PTES-INT-2 · Active Information Gathering →Perform periodic external penetration tests based on program requirements, no less than annually. External penetration testing must include enterprise and environmental reconnaissance to detect exploitable information.
CIS-18.2 · Perform Periodic External Penetration Tests →Quantify attempted attacks against the institution including phishing, DDoS, and reconnaissance traffic.
FFIEC-CAT-IRP-5 · External Threats →HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs →Apply D3FEND MODEL tactic - establishing the digital domain that the defender intends to defend. D3-AM Asset Inventory + D3-NM Network Mapping + D3-ID Identity Discovery + D3-NM-AM Asset Mapping + D3-SI System Inventory + D3-UA User Account Inventory + D3-SWI...
MITRE-D3FEND-Model-Tactic-System-Inventory-Network-Mapping-Identity-Discovery-Asset-Identification · MITRE D3FEND Model Tactic + System Inventory + Network Mapping + Identity Discovery + Asset Identification →Questions people ask about reconnaissance
What is Reconnaissance?
Why is Reconnaissance important for compliance?
Which compliance frameworks address Reconnaissance?
Where can I learn more about Reconnaissance?
See how Reconnaissance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.