Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareUmbreon | Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware. |
| T1014 Rootkit |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64(). |
| T1014 Rootkit |
MalwareHacking Team UEFI Rootkit | Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems. |
| T1014 Rootkit |
MalwareSkidmap | Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low. |
| T1014 Rootkit |
MalwareLine Dancer | Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms. |
| T1014 Rootkit |
MalwareREPTILE | REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections. |
| T1014 Rootkit |
MalwareZeroaccess | Zeroaccess is a kernel-mode rootkit. |
| T1014 Rootkit |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a rootkit on a system. |
| T1014 Rootkit |
MalwareUroburos | Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components. |
| T1014 Rootkit |
MalwareWinnti for Linux | Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity. |
| T1014 Rootkit |
MalwareHikit | |
| T1014 Rootkit |
MalwareDrovorub | Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view. |
| T1014 Rootkit |
MalwarePoisonIvy | PoisonIvy starts a rootkit from a malicious file dropped to disk. |
| T1014 Rootkit |
MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| T1014 Rootkit |
MalwareRamsay | Ramsay has included a rootkit to evade defenses. |
| T1014 Rootkit |
MalwareCarberp | Carberp has used user mode rootkit techniques to remain hidden on the system. |
| T1014 Rootkit |
MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| T1014 Rootkit |
MalwareHIDEDRV | HIDEDRV is a rootkit that hides certain operating system artifacts. |
| T1014 Rootkit |
MalwareHiddenWasp | HiddenWasp uses a rootkit to hook and implement functions on the system. |
| T1014 Rootkit |
MalwareWarzoneRAT | WarzoneRAT can include a rootkit to hide processes, files, and startup. |
| T1014 Rootkit |
ToolHTRAN | HTRAN can install a rootkit to hide network connections from the host OS. |
| T1016 System Network Configuration Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers victim IP information during initial installation stages. |
| T1016 System Network Configuration Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system. |
| T1016 System Network Configuration Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details. |
| T1016 System Network Configuration Discovery |
CampaignC0018 | During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network. |
| T1016 System Network Configuration Discovery |
CampaignShadowRay | During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses. |
| T1016 System Network Configuration Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary configured Claude Code to identify and gather system configurations of discovered devices. |
| T1016 System Network Configuration Discovery |
CampaignC0015 | During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host. |
| T1016 System Network Configuration Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments. |
| T1016 System Network Configuration Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used ipconfig for discovery on remote systems. |
| T1016 System Network Configuration Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands. |
| T1016 System Network Configuration Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands. |
| T1016 System Network Configuration Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`. |
| T1016 System Network Configuration Discovery |
CampaignC0017 | During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery. |
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1016 System Network Configuration Discovery |
GroupSideCopy | SideCopy has identified the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
GroupGALLIUM | GALLIUM used |
| T1016 System Network Configuration Discovery |
GroupAPT3 | A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1016 System Network Configuration Discovery |
GroupKimsuky | Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`. |
| T1016 System Network Configuration Discovery |
Groupadmin@338 | admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: |
| T1016 System Network Configuration Discovery |
GroupVolt Typhoon | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1016 System Network Configuration Discovery |
GroupDragonfly | Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain. |
| T1016 System Network Configuration Discovery |
GroupmenuPass | menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1016 System Network Configuration Discovery |
GroupAPT32 | APT32 used the |
| T1016 System Network Configuration Discovery |
GroupHAFNIUM | HAFNIUM has collected IP information via IPInfo. |
| T1016 System Network Configuration Discovery |
GroupMuddyWater | MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1016 System Network Configuration Discovery |
GroupNaikon | Naikon uses commands such as |
| T1016 System Network Configuration Discovery |
GroupTeamTNT | TeamTNT has enumerated the host machine’s IP address. |
| T1016 System Network Configuration Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on network interfaces, including the MAC address. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.