Real-world descriptions of how a group, tool or campaign used a technique.
54 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareTrickBot | TrickBot can enumerate computers and network devices. |
| T1018 Remote System Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to identify remote hosts on connected networks. |
| T1018 Remote System Discovery |
Malwareyty | yty uses the |
| T1018 Remote System Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| T1018 Remote System Discovery |
MalwareRansomHub | RansomHub can enumerate all accessible machines from the infected system. |
| T1018 Remote System Discovery |
MalwareHavoc | Havoc features a module capable of host enumeration. |
| T1018 Remote System Discovery |
MalwareGomir | Gomir probes arbitrary network endpoints for TCP connectivity. |
| T1018 Remote System Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses Windows Management Instrumentation to enumerate all systems in the network. |
| T1018 Remote System Discovery |
MalwareDUSTTRAP | DUSTTRAP can use `ping` to identify remote hosts within the victim network. |
| T1018 Remote System Discovery |
MalwareBADHATCH | BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer. |
| T1018 Remote System Discovery |
MalwareConti | Conti has the ability to discover hosts on a target network. |
| T1018 Remote System Discovery |
MalwareDiavol | Diavol can use the ARP table to find remote hosts to scan. |
| T1018 Remote System Discovery |
MalwareBlackCat | BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks. |
| T1018 Remote System Discovery |
MalwareDRATzarus | DRATzarus can search for other machines connected to compromised host and attempt to map the network. |
| T1018 Remote System Discovery |
MalwareSHOTPUT | SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain. |
| T1018 Remote System Discovery |
MalwareFlagpro | Flagpro has been used to execute |
| T1018 Remote System Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments. |
| T1018 Remote System Discovery |
MalwareRemsec | Remsec can ping or traceroute a remote host. |
| T1018 Remote System Discovery |
MalwareSykipot | Sykipot may use |
| T1018 Remote System Discovery |
MalwareEpic | Epic uses the |
| T1018 Remote System Discovery |
MalwareUSBferry | USBferry can use |
| T1018 Remote System Discovery |
MalwareWannaCry | WannaCry scans its local network segment for remote systems to try to exploit and copy itself to. |
| T1018 Remote System Discovery |
MalwareLODEINFO | LODEINFO can run `net view` and `net view /domain` for network discovery. |
| T1018 Remote System Discovery |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE command and execution module can perform target system enumeration. |
| T1018 Remote System Discovery |
MalwareShamoon | Shamoon scans the C-class subnet of the IPs on the victim's interfaces. |
| T1018 Remote System Discovery |
MalwareBlack Basta | Black Basta can use LDAP queries to connect to AD and iterate over connected workstations. |
| T1018 Remote System Discovery |
MalwareBazar | Bazar can enumerate remote systems using |
| T1018 Remote System Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1018 Remote System Discovery |
MalwareMgBot | MgBot includes modules for performing ARP scans of local connected systems. |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1018 Remote System Discovery |
MalwareCarbon | Carbon uses the |
| T1018 Remote System Discovery |
MalwareFunnyDream | FunnyDream can collect information about hosts on the victim network. |
| T1018 Remote System Discovery |
MalwareKwampirs | Kwampirs collects a list of available servers with the command |
| T1018 Remote System Discovery |
MalwarePoetRAT | PoetRAT used Nmap for remote system discovery. |
| T1018 Remote System Discovery |
MalwareKinsing | Kinsing has used a script to parse files like |
| T1018 Remote System Discovery |
MalwarenjRAT | njRAT can identify remote hosts on connected networks. |
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1018 Remote System Discovery |
MalwareIndustroyer | Industroyer can enumerate remote computers in the compromised network. |
| T1018 Remote System Discovery |
MalwareQakBot | QakBot can identify remote systems through the |
| T1018 Remote System Discovery |
MalwareComnie | Comnie runs the |
| T1018 Remote System Discovery |
MalwareOSInfo | OSInfo performs a connection test to discover remote systems in the network |
| T1018 Remote System Discovery |
MalwareBitPaymer | BitPaymer can use |
| T1018 Remote System Discovery |
MalwareHermeticWizard | HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.` |
| T1018 Remote System Discovery |
ToolNet | Commands such as |
| T1018 Remote System Discovery |
ToolBloodHound | BloodHound can enumerate and collect the properties of domain computers, including domain controllers. |
| T1018 Remote System Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate and collect the properties of domain computers. |
| T1018 Remote System Discovery |
ToolArp | Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems. |
| T1018 Remote System Discovery |
ToolROADTools | ROADTools can enumerate Azure AD systems and devices. |
| T1018 Remote System Discovery |
ToolNltest | Nltest may be used to enumerate remote domain controllers using options such as |
| T1018 Remote System Discovery |
ToolNBTscan | NBTscan can list NetBIOS computer names. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.