Research session unavailable. No participant research session is associated with this browser. Use the participant access link supplied by the facilitator.
← Back to dashboard
TA0043 Reconnaissance · T1595.003 · Wordlist Scanning

Recognize wordlist-scanning behavior

Lesson Purpose

What you are learning

Study how repeated requests for candidate hostnames, URLs, or resource names can appear in defensive telemetry.

Learning Objectives
Why This Matters

Vulnerability scanning helps organizations identify known weaknesses and configuration issues before they are abused. Results still require interpretation: scanner output can contain false positives, incomplete evidence, or findings whose practical risk depends on environmental context. Defenders therefore use scan results as inputs to validation, risk assessment, patching, and compensating-control decisions.

Exercise

Follow the exercise instructions provided by the trainer for this lesson.

Concept Lesson Completion

This module is a bounded ATT&CK/defender-analysis lesson. It does not require target interaction or submission of offensive findings.

Learning Moment

The key learning goal is recognizing a high-volume pattern of guessed resource names and understanding how defenders can baseline and detect that behavior.

Defender Perspective

Web access logs, DNS telemetry, WAF events, and rate-limit alerts can reveal repeated requests for nonexistent or uncommon resource names.