Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareReaver | Reaver collects the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1016 System Network Configuration Discovery |
MalwareS-Type | S-Type has used `ipconfig /all` on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareRemsec | Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1016 System Network Configuration Discovery |
MalwareSykipot | Sykipot may use |
| T1016 System Network Configuration Discovery |
MalwareExplosive | Explosive has collected the MAC address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareXbash | Xbash can collect IP addresses and local intranet information from a victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareEpic | Epic uses the |
| T1016 System Network Configuration Discovery |
MalwareLightNeuron | LightNeuron gathers information about network adapters using the Win32 API call |
| T1016 System Network Configuration Discovery |
MalwareCuba | Cuba can retrieve the ARP cache from the local system by using |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1016 System Network Configuration Discovery |
MalwareNanHaiShu | NanHaiShu can gather information about the victim proxy server. |
| T1016 System Network Configuration Discovery |
MalwareNGLite | NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier. |
| T1016 System Network Configuration Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines. |
| T1016 System Network Configuration Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the domain of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command. |
| T1016 System Network Configuration Discovery |
MalwareElise | Elise executes |
| T1016 System Network Configuration Discovery |
MalwareUSBferry | USBferry can detect the infected machine's network topology using |
| T1016 System Network Configuration Discovery |
MalwareWannaCry | WannaCry will attempt to determine the local network segment it is a part of. |
| T1016 System Network Configuration Discovery |
MalwareTSCookie | TSCookie has the ability to identify the IP of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareLatrodectus | Latrodectus can discover the IP and MAC address of a targeted host. |
| T1016 System Network Configuration Discovery |
MalwareSaint Bot | Saint Bot can collect the IP address of a victim machine. |
| T1016 System Network Configuration Discovery |
MalwarePay2Key | Pay2Key can identify the IP and MAC addresses of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareLODEINFO | LODEINFO can enumerate the MAC address of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareCharmPower | CharmPower has the ability to use |
| T1016 System Network Configuration Discovery |
MalwareQUADAGENT | QUADAGENT gathers the current domain the victim system belongs to. |
| T1016 System Network Configuration Discovery |
MalwareSagerunex | Sagerunex will gather system information such as MAC and IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareSys10 | Sys10 collects the local IP address of the victim and sends it to the C2. |
| T1016 System Network Configuration Discovery |
MalwareRoyal | Royal can enumerate IP addresses using `GetIpAddrTable`. |
| T1016 System Network Configuration Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information on the network configuration of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBandook | Bandook has a command to get the public IP address from a system. |
| T1016 System Network Configuration Discovery |
MalwarePipeMon | PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon. |
| T1016 System Network Configuration Discovery |
MalwareMagicRAT | MagicRAT collects system network information using commands such as `ipconfig /all`. |
| T1016 System Network Configuration Discovery |
MalwareKONNI | KONNI can collect the IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareT9000 | T9000 gathers and beacons the MAC and IP addresses during installation. |
| T1016 System Network Configuration Discovery |
MalwareShamoon | Shamoon obtains the target's IP address and local network segment. |
| T1016 System Network Configuration Discovery |
MalwareJHUHUGIT | A JHUHUGIT variant gathers network interface card information. |
| T1016 System Network Configuration Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect IP information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
Malwaredown_new | down_new has the ability to identify the MAC address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareIxeshe | Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system. |
| T1016 System Network Configuration Discovery |
MalwareRedLine Stealer | RedLine Stealer can enumeate information about victims’ systems including IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareCatchamas | Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareRogueRobin | RogueRobin gathers the IP address and domain from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareBoxCaon | BoxCaon can collect the victim's MAC address by using the |
| T1016 System Network Configuration Discovery |
MalwareSDBbot | SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMosquito | Mosquito uses the |
| T1016 System Network Configuration Discovery |
MalwareQUIETCANARY | QUIETCANARY can identify the default proxy setting on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareGrandoreiro | Grandoreiro can determine the IP and physical location of the compromised host via IPinfo. |
| T1016 System Network Configuration Discovery |
MalwareWellMail | WellMail can identify the IP address of the victim system. |
| T1016 System Network Configuration Discovery |
MalwareLiteDuke | LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.