Query Public AI Services: recognize the technique
What you are learning
Study how Query Public AI Services supports the Reconnaissance phase. This lesson uses a bounded defender-analysis exercise rather than executing the adversary behavior.
- Describe Query Public AI Services in ATT&CK terms.
- Explain how Query Public AI Services can support later stages of an operation.
- Name at least one defensive observation or control relevant to the behavior.
Pre-compromise activity often leaves indirect signals rather than exploit artifacts. Understanding these behaviors helps defenders connect public exposure, operational preparation, and later intrusion activity without overstating what any single observation proves.
Review the technique description and identify what evidence a defender could use to recognize, investigate, or reduce the risk of this behavior. No external target interaction is required.
This module is a bounded ATT&CK/defender-analysis lesson. It does not require target interaction or submission of offensive findings.
Query Public AI Services is part of Reconnaissance; the goal is to understand the adversary objective and the defender-visible evidence, not to reproduce harmful activity.
Use asset inventory, identity controls, provider telemetry, threat intelligence, and change/audit records where applicable. Correlate multiple observations before assigning adversary intent.