ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareUmbreon

Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware.

T1014
Rootkit
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1014
Rootkit
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareSkidmap

Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.

T1014
Rootkit
MalwareLine Dancer

Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms.

T1014
Rootkit
MalwareREPTILE

REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections.

T1014
Rootkit
MalwareZeroaccess

Zeroaccess is a kernel-mode rootkit.

T1014
Rootkit
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a rootkit on a system.

T1014
Rootkit
MalwareUroburos

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

T1014
Rootkit
MalwareWinnti for Linux

Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity.

T1014
Rootkit
MalwareHikit

Hikit is a Rootkit that has been used by Axiom.

T1014
Rootkit
MalwareDrovorub

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

T1014
Rootkit
MalwarePoisonIvy

PoisonIvy starts a rootkit from a malicious file dropped to disk.

T1014
Rootkit
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareRamsay

Ramsay has included a rootkit to evade defenses.

T1014
Rootkit
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1014
Rootkit
MalwareHIDEDRV

HIDEDRV is a rootkit that hides certain operating system artifacts.

T1014
Rootkit
MalwareHiddenWasp

HiddenWasp uses a rootkit to hook and implement functions on the system.

T1014
Rootkit
MalwareWarzoneRAT

WarzoneRAT can include a rootkit to hide processes, files, and startup.

T1014
Rootkit
ToolHTRAN

HTRAN can install a rootkit to hide network connections from the host OS.

T1016
System Network Configuration Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers victim IP information during initial installation stages.

T1016
System Network Configuration Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.

T1016
System Network Configuration Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1016
System Network Configuration Discovery
CampaignC0018

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

T1016
System Network Configuration Discovery
CampaignShadowRay

During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses.

T1016
System Network Configuration Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary configured Claude Code to identify and gather system configurations of discovered devices.

T1016
System Network Configuration Discovery
CampaignC0015

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

T1016
System Network Configuration Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments.

T1016
System Network Configuration Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used ipconfig for discovery on remote systems.

T1016
System Network Configuration Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands.

T1016
System Network Configuration Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands.

T1016
System Network Configuration Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`.

T1016
System Network Configuration Discovery
CampaignC0017

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

T1016
System Network Configuration Discovery
GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1016
System Network Configuration Discovery
GroupSideCopy

SideCopy has identified the IP address of a compromised host.

T1016
System Network Configuration Discovery
GroupGALLIUM

GALLIUM used ipconfig /all to obtain information about the victim network configuration. The group also ran a modified version of NBTscan to identify available NetBIOS name servers.

T1016
System Network Configuration Discovery
GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1016
System Network Configuration Discovery
GroupKimsuky

Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`.

T1016
System Network Configuration Discovery
Groupadmin@338

admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: ipconfig /all >> %temp%\download

T1016
System Network Configuration Discovery
GroupVolt Typhoon

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.

T1016
System Network Configuration Discovery
GroupAPT41

APT41 collected MAC addresses from victim machines.

T1016
System Network Configuration Discovery
GroupDragonfly

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.

T1016
System Network Configuration Discovery
GroupmenuPass

menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions.

T1016
System Network Configuration Discovery
GroupAPT32

APT32 used the ipconfig /all command to gather the IP address from the system.

T1016
System Network Configuration Discovery
GroupHAFNIUM

HAFNIUM has collected IP information via IPInfo.

T1016
System Network Configuration Discovery
GroupMuddyWater

MuddyWater has used malware to collect the victim’s IP address and domain name.

T1016
System Network Configuration Discovery
GroupNaikon

Naikon uses commands such as netsh interface show to discover network interface settings.

T1016
System Network Configuration Discovery
GroupTeamTNT

TeamTNT has enumerated the host machine’s IP address.

T1016
System Network Configuration Discovery
GroupSidewinder

Sidewinder has used malware to collect information on network interfaces, including the MAC address.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.