Real-world descriptions of how a group, tool or campaign used a technique.
61 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
MalwareTorisma | Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections. |
| T1049 System Network Connections Discovery |
MalwarePOWRUNER | POWRUNER may collect active network connections by running |
| T1049 System Network Connections Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections. |
| T1049 System Network Connections Discovery |
MalwareSardonic | Sardonic has the ability to execute the `netstat` command. |
| T1049 System Network Connections Discovery |
MalwareRedLeaves | RedLeaves can enumerate drives and Remote Desktop sessions. |
| T1049 System Network Connections Discovery |
MalwareGravityRAT | GravityRAT uses the |
| T1049 System Network Connections Discovery |
MalwareNETWIRE | NETWIRE can capture session logon details from a compromised host. |
| T1049 System Network Connections Discovery |
MalwarePyDCrypt | PyDCrypt has used netsh to find RPC connections on remote machines. |
| T1049 System Network Connections Discovery |
MalwareAria-body | Aria-body has the ability to gather TCP and UDP table status listings. |
| T1049 System Network Connections Discovery |
MalwareBADHATCH | BADHATCH can execute `netstat.exe -f` on a compromised machine. |
| T1049 System Network Connections Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather information on network connections. |
| T1049 System Network Connections Discovery |
MalwareMafalda | Mafalda can use the |
| T1049 System Network Connections Discovery |
MalwareVolgmer | Volgmer can gather information about TCP connection state. |
| T1049 System Network Connections Discovery |
MalwareOkrum | Okrum was seen using NetSess to discover NetBIOS sessions. |
| T1049 System Network Connections Discovery |
MalwareConti | Conti can enumerate routine network connections from a compromised host. |
| T1049 System Network Connections Discovery |
MalwareLucifer | Lucifer can identify the IP and port numbers for all remote connections from the compromised host. |
| T1049 System Network Connections Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about local network connections using netstat. |
| T1049 System Network Connections Discovery |
MalwareSHOTPUT | |
| T1049 System Network Connections Discovery |
MalwareFlagpro | Flagpro has been used to execute |
| T1049 System Network Connections Discovery |
MalwareBabuk | Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption. |
| T1049 System Network Connections Discovery |
MalwarePlugX | PlugX has a module for enumerating TCP and UDP network connections and associated processes using the |
| T1049 System Network Connections Discovery |
MalwareRemsec | Remsec can obtain a list of active connections and open ports. |
| T1049 System Network Connections Discovery |
MalwareSykipot | Sykipot may use |
| T1049 System Network Connections Discovery |
MalwareEpic | Epic uses the |
| T1049 System Network Connections Discovery |
MalwareCuba | Cuba can use the function |
| T1049 System Network Connections Discovery |
MalwareUSBferry | USBferry can use |
| T1049 System Network Connections Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use netstat to collect a list of network connections. |
| T1049 System Network Connections Discovery |
MalwareKONNI | KONNI has used |
| T1049 System Network Connections Discovery |
MalwareSibot | Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine. |
| T1049 System Network Connections Discovery |
MalwareMESSAGETAP | After loading the keyword and phone data files, MESSAGETAP begins monitoring all network connections to and from the victim server. |
| T1049 System Network Connections Discovery |
MalwareRATANKBA | RATANKBA uses |
| T1049 System Network Connections Discovery |
MalwareZebrocy | Zebrocy uses |
| T1049 System Network Connections Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1049 System Network Connections Discovery |
MalwareCobalt Strike | Cobalt Strike can produce a sessions report from compromised hosts. |
| T1049 System Network Connections Discovery |
MalwareCarbon | Carbon uses the |
| T1049 System Network Connections Discovery |
MalwareRamsay | Ramsay can use |
| T1049 System Network Connections Discovery |
MalwareKwampirs | Kwampirs collects a list of active and listening connections by using the command |
| T1049 System Network Connections Discovery |
MalwareEgregor | Egregor can enumerate all connected drives. |
| T1049 System Network Connections Discovery |
MalwareMaze | Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine. |
| T1049 System Network Connections Discovery |
MalwareLunarWeb | LunarWeb can enumerate system network connections. |
| T1049 System Network Connections Discovery |
MalwareQakBot | QakBot can use |
| T1049 System Network Connections Discovery |
MalwarejRAT | jRAT can list network connections. |
| T1049 System Network Connections Discovery |
MalwareWaterbear | Waterbear can use API hooks on `GetExtendedTcpTable` to retrieve a table containing a list of TCP endpoints available to the application. |
| T1049 System Network Connections Discovery |
MalwareComnie | Comnie executes the |
| T1049 System Network Connections Discovery |
MalwareOSInfo | OSInfo enumerates the current network connections similar to |
| T1049 System Network Connections Discovery |
MalwareLizar | Lizar has a plugin to retrieve information about all active network sessions on the infected server. |
| T1049 System Network Connections Discovery |
MalwareDtrack | Dtrack can collect network and active connection information. |
| T1049 System Network Connections Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate open ports on a victim machine. |
| T1049 System Network Connections Discovery |
ToolNet | Commands such as |
| T1049 System Network Connections Discovery |
ToolShimRatReporter | ShimRatReporter used the Windows function |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.