ATLAS Landscape
AML.T0006

Active Scanning

An adversary may probe or scan the victim system to gather information for targeting. This is distinct from other reconnaissance techniques that do not involve direct interaction with the victim system. Adversaries may scan for open ports on a potential victim's network, which can indicate specific services or tools the victim is utilizing. This could include a scan for tools related to AI DevOps or AI services themselves such as public AI chat agents (ex: [Copilot Studio Hunter](https://github.com/mbrg/power-pwn/wiki/Modules:-Copilot-Studio-Hunter-%E2%80%90-Enum)). They can also send emails to organization service addresses and inspect the replies for indicators that an AI agent is managing the inbox. Information gained from Active Scanning may yield targets that provide opportunities for other forms of reconnaissance such as [Search Open Technical Databases](/techniques/AML.T0000), [Search Open AI Vulnerability Analysis](/techniques/AML.T0001), or [Gather RAG-Indexed Targets](/techniques/AML.T0064).

Severity CVE CVSS
CRITICAL CVE-2023-48022 9.8
CRITICAL CVE-2024-47167 9.8
CRITICAL CVE-2023-6019 9.8
CRITICAL CVE-2024-41120 9.8
CRITICAL CVE-2025-32444 9.8
CRITICAL CVE-2024-9052 9.8
CRITICAL CVE-2026-41268 9.8
CRITICAL CVE-2024-41118 9.8
CRITICAL CVE-2025-47241 9.3
CRITICAL CVE-2026-7482 9.1
HIGH CVE-2026-28416 8.6
HIGH CVE-2024-32965 8.6
HIGH CVE-2024-4325 8.6
HIGH CVE-2025-65958 8.5
HIGH CVE-2026-41271 8.3
HIGH CVE-2024-35199 8.2
HIGH GHSA-75hx-xj24-mqrw 8.2
HIGH CVE-2025-61784 8.1
HIGH CVE-2024-3095 7.7
HIGH CVE-2024-36421 7.5
HIGH CVE-2026-28414 7.5
HIGH CVE-2026-33484 7.5
HIGH CVE-2026-0599 7.5
HIGH CVE-2025-66786 7.5
HIGH CVE-2025-65805 7.5
HIGH CVE-2025-59425 7.5
HIGH CVE-2025-6386 7.5
HIGH CVE-2025-30202 7.5
HIGH CVE-2024-8020 7.5
HIGH CVE-2024-39722 7.5
HIGH CVE-2024-39719 7.5
HIGH CVE-2024-36420 7.5
HIGH CVE-2022-41899 7.5
HIGH CVE-2025-59527 7.5
HIGH CVE-2026-40114 7.2
HIGH CVE-2026-24779 7.1
MEDIUM GHSA-pgx6-7jcq-2qff 6.8
MEDIUM CVE-2026-3340 6.5
MEDIUM CVE-2024-2206 6.5
MEDIUM CVE-2026-7844 6.3
MEDIUM CVE-2026-5530 6.3
MEDIUM CVE-2025-67743 6.3
MEDIUM CVE-2026-27482 5.9
MEDIUM CVE-2026-40151 5.3
MEDIUM CVE-2025-63390 5.3
MEDIUM CVE-2026-40086 5.3
MEDIUM CVE-2026-28786 4.3
MEDIUM CVE-2026-44559 4.3
MEDIUM CVE-2024-47168 4.3
MEDIUM CVE-2026-26019 4.1
LOW CVE-2024-47869 3.7
LOW CVE-2026-26013 3.7
LOW GHSA-r7w7-9xr2-qq2r 3.1
LOW CVE-2024-7038 2.7
LOW CVE-2026-7847 2.6
LOW CVE-2025-25183 2.6
LOW GHSA-j4c5-89f5-f3pm
CRITICAL CVE-2025-32428
CRITICAL CVE-2025-34351
MEDIUM GHSA-jj6q-rrrf-h66h
UNKNOWN CVE-2025-15063
UNKNOWN CVE-2024-1729
UNKNOWN CVE-2024-1183