Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is service discovery?

Service discovery is how somebody finds out what network services or applications are available on another system.

That might reveal remote desktop, file sharing, a web application, a database or an administrative interface. Once a useful service appears, it may become the next target.

A port can tell you where to look next

Suppose network discovery identifies a server at 10.24.8.17.

A later query finds:

Port Likely service Useful next question
445 SMB / Windows file sharing Was a share later accessed?
3389 Remote Desktop Was there a successful remote login?
443 HTTPS / web application Which application answered and was it used?
22 SSH Was an SSH session later created?

The important point is not memorising port numbers. It is that the response may reveal a service that can then be followed into its own logs.

Look for the source, target and response

Useful evidence may come from several places:

  • the process or tool that sent the query;
  • firewall or network records showing the destination and port;
  • the target service showing the request;
  • authentication records;
  • application logs; and
  • any later process or session activity on the target.

A service banner or open port can explain why a machine became interesting. It does not prove that access succeeded.

Follow the service into later records

If Remote Desktop appears on a server, look for later RDP authentication and session activity.

If file sharing appears, look for share access and file events.

If a web application responds, identify the application and check its access and authentication logs.

DiscoveryPort 3389 respondsThe session learns that Remote Desktop appears to be available.
AuthenticationLogin attempt recordedThe target now has evidence of an attempt to use the service.
UseInteractive session createdLater records show whether access actually succeeded.

This is why service discovery is useful: it gives you a route into a more specific set of records.

Normal tools may do the same thing

Vulnerability scanners, inventory systems and administrators all check services.

Compare the source, timing, target range and what follows.

A scheduled vulnerability scan across every server is one thing. A new process on a compromised workstation finding RDP on one server and then immediately trying to log in is another.

Could legitimate administration look like reconnaissance? deals with that comparison directly.

The practical point is: service discovery tells you what appeared to be available. The next job is to see whether anybody actually used it.

Reference: CIM-123Cyber Incidents & Offender Methods