Recognize wordlist-scanning behavior
What you are learning
Study how repeated requests for candidate hostnames, URLs, or resource names can appear in defensive telemetry.
- Explain the purpose of vulnerability-oriented scanning in an authorized assessment.
- Distinguish vulnerability evidence from a confirmed compromise or exploit.
- Describe how defenders can use scanning results to prioritize verification and remediation.
Vulnerability scanning helps organizations identify known weaknesses and configuration issues before they are abused. Results still require interpretation: scanner output can contain false positives, incomplete evidence, or findings whose practical risk depends on environmental context. Defenders therefore use scan results as inputs to validation, risk assessment, patching, and compensating-control decisions.
Follow the exercise instructions provided by the trainer for this lesson.
This module is a bounded ATT&CK/defender-analysis lesson. It does not require target interaction or submission of offensive findings.
The key learning goal is recognizing a high-volume pattern of guessed resource names and understanding how defenders can baseline and detect that behavior.
Web access logs, DNS telemetry, WAF events, and rate-limit alerts can reveal repeated requests for nonexistent or uncommon resource names.