Skip to main content

Threats Tagged 'kill-chain:reconnaissance'

View all threats tagged with 'kill-chain:reconnaissance'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: kill-chain:reconnaissance

Threats Tagged 'kill-chain:reconnaissance'

Click on any threat for detailed analysis and mitigation recommendations

The KRVTZ-NET IDS alerts for 2026-05-23 report observed network reconnaissance activity identified through OSINT sources. The alerts primarily indicate outbound traffic associated with Baidu Spider Crawler User-Agent IP addresses. No specific vulnerabilities or exploits are identified, and no affected product versions are noted. There is no patch or remediation required as this is an observation of network scanning or crawling activity. The severity is assessed as low given the nature of the activity and lack of confirmed exploitation.

Join the discussion

The KRVTZ-NET IDS alerts from 2026-05-21 report network activity consistent with reconnaissance targeting Fortigate VPN devices. Specifically, multiple IP addresses were observed making repeated GET requests to the /remote/logincheck endpoint, which is associated with CVE-2023-27997, a known vulnerability in Fortigate VPN. Several other IPs exhibited suspicious or test user-agent strings, indicating scanning or probing behavior. No active exploitation or confirmed compromises are reported. The activity is categorized as low severity due to its reconnaissance nature without evidence of exploitation.

Join the discussion

The KRVTZ-NET IDS alerts for 2026-05-20 report observed network reconnaissance activity involving two IP addresses. One IP (5.255.102.136) made inbound requests to a hidden environment file, categorized as informational. Another IP (2001:470:1:fb5::1a0) performed repeated GET requests to the Fortigate VPN logincheck endpoint, associated with CVE-2023-27997, a known vulnerability. There is no indication of confirmed exploitation or compromise. The event is classified as reconnaissance with low severity and no known exploits in the wild.

Join the discussion

The KRVTZ-NET IDS alerts for 2026-05-18 represent a collection of network reconnaissance and scanning activities detected by an intrusion detection system. The alerts include IP addresses associated with requests to hidden environment files, test user-agent probes, webcrawler scans, and exploit attempts targeting Fortigate VPN (CVE-2023-27997). Additional indicators include SQL injection time delay probes and Laravel debug mode information disclosure scans. These events are categorized as reconnaissance and informational observations rather than confirmed active exploits or compromises. No known exploits in the wild or successful attacks are reported in this feed. The overall severity is assessed as low based on the nature of the activity and lack of confirmed exploitation.

Join the discussion

The KRVTZ-NET IDS alerts for 2026-05-17 report multiple network reconnaissance and scanning activities, including repeated exploit attempts against Fortigate VPN (CVE-2023-27997) and a React Server Components vulnerability (CVE-2025-55182). Several IP addresses were observed making suspicious requests such as repeated GET requests to /remote/logincheck and attempts to access hidden environment files. These activities are indicative of preliminary probing rather than confirmed exploitation. No known exploits in the wild or confirmed breaches have been reported. The overall severity is assessed as low due to the absence of confirmed successful attacks.

Join the discussion

Showing 1 to 10 of 129 results

Filters:Tag: kill-chain:reconnaissance
Page 1 of 13
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses