Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSibot | Sibot checked if the compromised system is configured to use proxies. |
| T1016 System Network Configuration Discovery |
MalwareBazar | Bazar can collect the IP address and NetBIOS name of an infected machine. |
| T1016 System Network Configuration Discovery |
MalwareKobalos | Kobalos can record the IP address of the target machine. |
| T1016 System Network Configuration Discovery |
MalwareRATANKBA | RATANKBA gathers the victim’s IP address via the |
| T1016 System Network Configuration Discovery |
MalwareBADCALL | BADCALL collects the network adapter information. |
| T1016 System Network Configuration Discovery |
MalwareMoonWind | MoonWind obtains the victim IP address. |
| T1016 System Network Configuration Discovery |
MalwareRyuk | Ryuk has called |
| T1016 System Network Configuration Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced IP Scanner tool. |
| T1016 System Network Configuration Discovery |
MalwareZebrocy | Zebrocy runs the |
| T1016 System Network Configuration Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1016 System Network Configuration Discovery |
MalwareCobalt Strike | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1016 System Network Configuration Discovery |
MalwareSUNBURST | SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information. |
| T1016 System Network Configuration Discovery |
MalwareHotCroissant | HotCroissant has the ability to identify the IP address of the compromised machine. |
| T1016 System Network Configuration Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareValak | Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine. |
| T1016 System Network Configuration Discovery |
MalwareMilan | Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings. |
| T1016 System Network Configuration Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareTaidoor | Taidoor has collected the MAC address of a compromised host; it can also use |
| T1016 System Network Configuration Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names. |
| T1016 System Network Configuration Discovery |
MalwareNanoCore | NanoCore gathers the IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareTajMahal | TajMahal has the ability to identify the MAC address on an infected host. |
| T1016 System Network Configuration Discovery |
MalwareCarbon | Carbon can collect the IP address of the victims and other computers on the network using the commands: |
| T1016 System Network Configuration Discovery |
MalwareCalisto | Calisto runs the |
| T1016 System Network Configuration Discovery |
MalwarePisloader | Pisloader has a command to collect the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareRamsay | Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables. |
| T1016 System Network Configuration Discovery |
MalwareRevenge RAT | Revenge RAT collects the IP address and MAC address from the system. |
| T1016 System Network Configuration Discovery |
MalwareMacMa | MacMa can collect IP addresses from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareFunnyDream | FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies. |
| T1016 System Network Configuration Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the IP address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareSysUpdate | SysUpdate can collected the IP address and domain name of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareKwampirs | Kwampirs collects network adapter and interface information by using the commands |
| T1016 System Network Configuration Discovery |
MalwareDEADEYE | DEADEYE can discover the DNS domain name of a targeted system. |
| T1016 System Network Configuration Discovery |
MalwareLAMEHUG | LAMEHUG can enumerate network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwareKessel | Kessel has collected the DNS address of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareGrimAgent | GrimAgent can enumerate the IP and domain of a target system. |
| T1016 System Network Configuration Discovery |
MalwareLokibot | Lokibot has the ability to discover the domain name of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareFELIXROOT | FELIXROOT collects information about the network including the IP address and DHCP server. |
| T1016 System Network Configuration Discovery |
MalwarePenquin | Penquin can report the IP of the compromised host to attacker controlled infrastructure. |
| T1016 System Network Configuration Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1016 System Network Configuration Discovery |
MalwareCreepySnail | CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings. |
| T1016 System Network Configuration Discovery |
MalwareTroll Stealer | Troll Stealer collects the MAC address of victim devices. |
| T1016 System Network Configuration Discovery |
MalwareManjusaka | Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes. |
| T1016 System Network Configuration Discovery |
MalwareIceApple | The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks. |
| T1016 System Network Configuration Discovery |
MalwareJPIN | JPIN can obtain network information, including DNS, IP, and proxies. |
| T1016 System Network Configuration Discovery |
MalwareSideTwist | SideTwist has the ability to collect the domain name on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1016 System Network Configuration Discovery |
MalwareLunarWeb | LunarWeb can use shell commands to discover network adapters and configuration. |
| T1016 System Network Configuration Discovery |
MalwareOctopus | Octopus can collect the host IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareQilin | Qilin can accept a command line argument identifying specific IPs. |
| T1016 System Network Configuration Discovery |
MalwareSoreFang | SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.