Real-world descriptions of how a group, tool or campaign used a technique.
232 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
Malwarecd00r | cd00r can discover the IP for the network interface on the compromised device. |
| T1016 System Network Configuration Discovery |
MalwarePowerDuke | PowerDuke has a command to get the victim's domain and NetBIOS name. |
| T1016 System Network Configuration Discovery |
MalwareEKANS | EKANS can determine the domain of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected the victim machine's local IP address information and MAC address. |
| T1016 System Network Configuration Discovery |
MalwareNinja | Ninja can enumerate the IP address on compromised systems. |
| T1016 System Network Configuration Discovery |
MalwarePikabot | Pikabot gathers victim network information through commands such as |
| T1016 System Network Configuration Discovery |
MalwareAmadey | Amadey can identify the IP address of a victim machine. |
| T1016 System Network Configuration Discovery |
MalwareProxysvc | Proxysvc collects the network adapter information and domain/username information based on current remote sessions. |
| T1016 System Network Configuration Discovery |
MalwareOrz | Orz can gather victim proxy information. |
| T1016 System Network Configuration Discovery |
MalwareTorisma | Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address. |
| T1016 System Network Configuration Discovery |
MalwareNOKKI | NOKKI can gather information on the victim IP address. |
| T1016 System Network Configuration Discovery |
Malwareyty | yty runs |
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1016 System Network Configuration Discovery |
MalwareStuxnet | Stuxnet collects the IP address of a compromised system. |
| T1016 System Network Configuration Discovery |
MalwarePOWRUNER | POWRUNER may collect network configuration data by running |
| T1016 System Network Configuration Discovery |
MalwareKOPILUWAK | KOPILUWAK can use Arp to discover a target's network configuration setttings. |
| T1016 System Network Configuration Discovery |
MalwareSardonic | Sardonic has the ability to execute the `ipconfig` command. |
| T1016 System Network Configuration Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1016 System Network Configuration Discovery |
MalwareKEYMARBLE | KEYMARBLE gathers the MAC address of the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareRedLeaves | RedLeaves can obtain information about network parameters. |
| T1016 System Network Configuration Discovery |
MalwareFelismus | Felismus collects the victim LAN IP address and sends it to the C2 server. |
| T1016 System Network Configuration Discovery |
MalwareGeminiDuke | GeminiDuke collects information on network settings and Internet proxy settings from the victim. |
| T1016 System Network Configuration Discovery |
MalwareHavoc | Havoc has a module for network enumeration including determining IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareGravityRAT | GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name. |
| T1016 System Network Configuration Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the local IP address, and external IP. |
| T1016 System Network Configuration Discovery |
MalwareStrongPity | StrongPity can identify the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwarexCaon | xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address. |
| T1016 System Network Configuration Discovery |
MalwarePLAINTEE | PLAINTEE uses the |
| T1016 System Network Configuration Discovery |
MalwareOceanSalt | OceanSalt can collect the victim’s IP address. |
| T1016 System Network Configuration Discovery |
MalwareBrave Prince | Brave Prince gathers network configuration information as well as the ARP cache. |
| T1016 System Network Configuration Discovery |
MalwareAppleSeed | AppleSeed can identify the IP of a targeted system. |
| T1016 System Network Configuration Discovery |
MalwareNETWIRE | NETWIRE can collect the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareJ-magic | J-magic can compare the host and remote IPs to check if a received packet is from the infected machine. |
| T1016 System Network Configuration Discovery |
MalwareiKitten | iKitten will look for the current IP address. |
| T1016 System Network Configuration Discovery |
MalwareGomir | Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses. |
| T1016 System Network Configuration Discovery |
MalwareAria-body | Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses API calls to enumerate the infected system's ARP table. |
| T1016 System Network Configuration Discovery |
MalwareBOLDMOVE | BOLDMOVE enumerates network interfaces on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareCrimson | Crimson contains a command to collect the victim MAC address and LAN IP. |
| T1016 System Network Configuration Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate infected system network information. |
| T1016 System Network Configuration Discovery |
MalwareTurian | Turian can retrieve the internal IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMachete | Machete collects the MAC address of the target computer and other network configuration information. |
| T1016 System Network Configuration Discovery |
MalwareAction RAT | Action RAT has the ability to collect the MAC address of an infected host. |
| T1016 System Network Configuration Discovery |
MalwareAvenger | Avenger can identify the domain of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about its IP addresses and MAC addresses. |
| T1016 System Network Configuration Discovery |
MalwarePUBLOAD | PUBLOAD has obtained information about local networks through the `ipconfig /all` command. |
| T1016 System Network Configuration Discovery |
MalwareGootloader | Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites. |
| T1016 System Network Configuration Discovery |
MalwarePingPull | PingPull can retrieve the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareWellMess | WellMess can identify the IP address and user domain on the target machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.