ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSTARWHALE

STARWHALE has the ability to collect the IP address of an infected host.

T1016
System Network Configuration Discovery
MalwareIndustroyer

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1016
System Network Configuration Discovery
MalwareKevin

Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`.

T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1016
System Network Configuration Discovery
MalwareShadowPad

ShadowPad has collected the domain name of the victim system.

T1016
System Network Configuration Discovery
MalwareAstaroth

Astaroth collects the external IP address from the system.

T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016
System Network Configuration Discovery
MalwarejRAT

jRAT can gather victim internal and external IPs.

T1016
System Network Configuration Discovery
MalwareDenis

Denis uses ipconfig to gather the IP address from the system.

T1016
System Network Configuration Discovery
MalwareComnie

Comnie uses ipconfig /all and route PRINT to identify network adapter and interface information.

T1016
System Network Configuration Discovery
MalwareOSInfo

OSInfo discovers the current domain information.

T1016
System Network Configuration Discovery
MalwareLizar

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1016
System Network Configuration Discovery
MalwareDtrack

Dtrack can collect the host's IP addresses using the ipconfig command.

T1016
System Network Configuration Discovery
MalwareLoudMiner

LoudMiner used a script to gather the IP address of the infected machine before sending to the C2.

T1016
System Network Configuration Discovery
MalwareAzorult

Azorult can collect host IP information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's proxy information.

T1016
System Network Configuration Discovery
MalwareFALLCHILL

FALLCHILL collects MAC address and local IP address information from the victim.

T1016
System Network Configuration Discovery
MalwareXORIndex Loader

XORIndex Loader has leveraged webservices to identify the public IP of the victim host.

T1016
System Network Configuration Discovery
MalwareSmall Sieve

Small Sieve can obtain the IP address of a victim host.

T1016
System Network Configuration Discovery
ToolShimRatReporter

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1016
System Network Configuration Discovery
ToolSliver

Sliver has the ability to gather network configuration information.

T1016
System Network Configuration Discovery
Toolevilginx2

evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent.

T1016
System Network Configuration Discovery
Toolipconfig

ipconfig can be used to display adapter configuration on Windows systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolArp

Arp can be used to display ARP configuration information on the host.

T1016
System Network Configuration Discovery
ToolEmpire

Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host.

T1016
System Network Configuration Discovery
Toolifconfig

ifconfig can be used to display adapter configuration on Unix systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolPcShare

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1016
System Network Configuration Discovery
ToolPoshC2

PoshC2 can enumerate network adapter information.

T1016
System Network Configuration Discovery
ToolAsyncRAT

AsyncRAT can enumerate the NetBIOS name on targeted machines.

T1016
System Network Configuration Discovery
ToolNltest

Nltest may be used to enumerate the parent domain of a local machine using /parentdomain.

T1016
System Network Configuration Discovery
Toolnbtstat

nbtstat can be used to discover local NetBIOS domain names.

T1016
System Network Configuration Discovery
ToolNBTscan

NBTscan can be used to collect MAC addresses.

T1016
System Network Configuration Discovery
Toolroute

route can be used to discover routing configuration information.

T1016
System Network Configuration Discovery
ToolCrackMapExec

CrackMapExec can collect DNS information from the targeted system.

T1016
System Network Configuration Discovery
ToolKoadic

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1016
System Network Configuration Discovery
ToolPupy

Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions.

T1016
System Network Configuration Discovery
ToolQuasarRAT

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1016
System Network Configuration Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to enumerate network interfaces.

T1016
System Network Configuration Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`.

T1016
System Network Configuration Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1016
System Network Configuration Discovery
MalwareBADFLICK

BADFLICK has captured victim IP address details.

T1016
System Network Configuration Discovery
MalwareDuqu

The reconnaissance modules used with Duqu can collect information on network configuration.

T1016.001
Internet Connection Discovery
MalwareQuietSieve

QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS).

T1016.001
Internet Connection Discovery
MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

T1016.001
Internet Connection Discovery
MalwarePUBLOAD

PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`.

T1016.001
Internet Connection Discovery
MalwareWoody RAT

Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks.

T1016.001
Internet Connection Discovery
MalwareSUGARUSH

SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.

T1016.001
Internet Connection Discovery
MalwareNeoichor

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.