ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareReaver

Reaver collects the victim's IP address.

T1016
System Network Configuration Discovery
MalwareBisonal

Bisonal can execute ipconfig on the victim’s machine.

T1016
System Network Configuration Discovery
MalwareS-Type

S-Type has used `ipconfig /all` on a compromised host.

T1016
System Network Configuration Discovery
MalwareRemsec

Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache.

T1016
System Network Configuration Discovery
MalwareSykipot

Sykipot may use ipconfig /all to gather system network configuration details.

T1016
System Network Configuration Discovery
MalwareExplosive

Explosive has collected the MAC address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareXbash

Xbash can collect IP addresses and local intranet information from a victim’s machine.

T1016
System Network Configuration Discovery
MalwareEpic

Epic uses the nbtstat -n and nbtstat -s commands on the victim’s machine.

T1016
System Network Configuration Discovery
MalwareLightNeuron

LightNeuron gathers information about network adapters using the Win32 API call GetAdaptersInfo.

T1016
System Network Configuration Discovery
MalwareCuba

Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.

T1016
System Network Configuration Discovery
MalwareClambling

Clambling can enumerate the IP address of a compromised machine.

T1016
System Network Configuration Discovery
MalwareNanHaiShu

NanHaiShu can gather information about the victim proxy server.

T1016
System Network Configuration Discovery
MalwareNGLite

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.

T1016
System Network Configuration Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1016
System Network Configuration Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command.

T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1016
System Network Configuration Discovery
MalwareUSBferry

USBferry can detect the infected machine's network topology using ipconfig and arp.

T1016
System Network Configuration Discovery
MalwareWannaCry

WannaCry will attempt to determine the local network segment it is a part of.

T1016
System Network Configuration Discovery
MalwareTSCookie

TSCookie has the ability to identify the IP of the infected host.

T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1016
System Network Configuration Discovery
MalwareSaint Bot

Saint Bot can collect the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwarePay2Key

Pay2Key can identify the IP and MAC addresses of the compromised host.

T1016
System Network Configuration Discovery
MalwareLODEINFO

LODEINFO can enumerate the MAC address of the compromised host.

T1016
System Network Configuration Discovery
MalwareCharmPower

CharmPower has the ability to use ipconfig to enumerate system network settings.

T1016
System Network Configuration Discovery
MalwareQUADAGENT

QUADAGENT gathers the current domain the victim system belongs to.

T1016
System Network Configuration Discovery
MalwareSagerunex

Sagerunex will gather system information such as MAC and IP addresses.

T1016
System Network Configuration Discovery
MalwareSys10

Sys10 collects the local IP address of the victim and sends it to the C2.

T1016
System Network Configuration Discovery
MalwareRoyal

Royal can enumerate IP addresses using `GetIpAddrTable`.

T1016
System Network Configuration Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information on the network configuration of a compromised host.

T1016
System Network Configuration Discovery
MalwareBandook

Bandook has a command to get the public IP address from a system.

T1016
System Network Configuration Discovery
MalwarePipeMon

PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon.

T1016
System Network Configuration Discovery
MalwareMagicRAT

MagicRAT collects system network information using commands such as `ipconfig /all`.

T1016
System Network Configuration Discovery
MalwareKONNI

KONNI can collect the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareT9000

T9000 gathers and beacons the MAC and IP addresses during installation.

T1016
System Network Configuration Discovery
MalwareShamoon

Shamoon obtains the target's IP address and local network segment.

T1016
System Network Configuration Discovery
MalwareJHUHUGIT

A JHUHUGIT variant gathers network interface card information.

T1016
System Network Configuration Discovery
MalwareBLUELIGHT

BLUELIGHT can collect IP information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwaredown_new

down_new has the ability to identify the MAC address of a compromised host.

T1016
System Network Configuration Discovery
MalwareIxeshe

Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system.

T1016
System Network Configuration Discovery
MalwareRedLine Stealer

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1016
System Network Configuration Discovery
MalwareCatchamas

Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRogueRobin

RogueRobin gathers the IP address and domain from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareBoxCaon

BoxCaon can collect the victim's MAC address by using the GetAdaptersInfo API.

T1016
System Network Configuration Discovery
MalwareSDBbot

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1016
System Network Configuration Discovery
MalwareMosquito

Mosquito uses the ipconfig command.

T1016
System Network Configuration Discovery
MalwareQUIETCANARY

QUIETCANARY can identify the default proxy setting on a compromised host.

T1016
System Network Configuration Discovery
MalwareGrandoreiro

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.

T1016
System Network Configuration Discovery
MalwareWellMail

WellMail can identify the IP address of the victim system.

T1016
System Network Configuration Discovery
MalwareLiteDuke

LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.