{"description": "Enterprise techniques used by Vulnerability Scanning, ATT&CK mitigation M1016 v1.1", "name": "Vulnerability Scanning (M1016)", "domain": "enterprise-attack", "versions": {"layer": "4.3", "attack": "10", "navigator": "4.5"}, "techniques": [{"score": 1, "techniqueID": "T1190", "showSubtechniques": false, "comment": "Regularly scan externally facing systems for vulnerabilities and establish procedures to rapidly patch systems when critical vulnerabilities are discovered through scanning and through public disclosure.(Citation: OWASP Top 10)"}, {"score": 1, "techniqueID": "T1210", "showSubtechniques": false, "comment": "Regularly scan the internal network for available services to identify new and potentially vulnerable services."}, {"score": 1, "techniqueID": "T1195", "showSubtechniques": true, "comment": "Continuous monitoring of vulnerability sources and the use of automatic and manual code review tools should also be implemented as well.(Citation: OWASP Top 10)"}, {"score": 1, "techniqueID": "T1195.001", "showSubtechniques": true, "comment": "Continuous monitoring of vulnerability sources and the use of automatic and manual code review tools should also be implemented as well.(Citation: OWASP Top 10)"}, {"score": 1, "techniqueID": "T1195.002", "showSubtechniques": true, "comment": "Continuous monitoring of vulnerability sources and the use of automatic and manual code review tools should also be implemented as well.(Citation: OWASP Top 10)"}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Vulnerability Scanning", "color": "#66b1ff"}]}