Discovery (MITRE ATT&CK TA0007) is the set of actions an adversary takes after gaining a foothold to learn the target environment and find the best paths to achieve objectives (privilege escalation, lateral movement, credential access, data access/exfiltration). Discovery includes enumerating users, groups, computers, services, network configuration, shares, listening ports, installed software, and security products. It’s often noisy but one of the earliest and most actionable signs of an intrusion treat bursts of enumeration from a host as potential active intrusion and escalate investigation.


Windows / Active Directory discovery commands

Host / system / identity

Accounts & groups

Processes, services & installed apps