Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.001 Internet Connection Discovery |
MalwareRising Sun | Rising Sun can test a connection to a specified network IP address over a specified port number. |
| T1016.001 Internet Connection Discovery |
MalwareDarkTortilla | DarkTortilla can check for internet connectivity by issuing HTTP GET requests. |
| T1016.001 Internet Connection Discovery |
MalwareGoldFinder | GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through. |
| T1016.001 Internet Connection Discovery |
MalwareNKAbuse | NKAbuse utilizes external services such as |
| T1016.001 Internet Connection Discovery |
MalwareMore_eggs | More_eggs has used HTTP GET requests to check internet connectivity. |
| T1016.001 Internet Connection Discovery |
MalwareSysUpdate | SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process. |
| T1016.001 Internet Connection Discovery |
MalwareQakBot | QakBot can measure the download speed on a targeted host. |
| T1016.002 Wi-Fi Discovery |
MalwareEmotet | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| T1016.002 Wi-Fi Discovery |
MalwareMachete | Machete uses the |
| T1016.002 Wi-Fi Discovery |
MalwarePUBLOAD | PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`. |
| T1016.002 Wi-Fi Discovery |
MalwareCharmPower | CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details. |
| T1016.002 Wi-Fi Discovery |
MalwareAgent Tesla | Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1018 Remote System Discovery |
MalwareTrickBot | TrickBot can enumerate computers and network devices. |
| T1018 Remote System Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to identify remote hosts on connected networks. |
| T1018 Remote System Discovery |
Malwareyty | yty uses the |
| T1018 Remote System Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| T1018 Remote System Discovery |
MalwareRansomHub | RansomHub can enumerate all accessible machines from the infected system. |
| T1018 Remote System Discovery |
MalwareHavoc | Havoc features a module capable of host enumeration. |
| T1018 Remote System Discovery |
MalwareGomir | Gomir probes arbitrary network endpoints for TCP connectivity. |
| T1018 Remote System Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses Windows Management Instrumentation to enumerate all systems in the network. |
| T1018 Remote System Discovery |
MalwareDUSTTRAP | DUSTTRAP can use `ping` to identify remote hosts within the victim network. |
| T1018 Remote System Discovery |
MalwareBADHATCH | BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer. |
| T1018 Remote System Discovery |
MalwareConti | Conti has the ability to discover hosts on a target network. |
| T1018 Remote System Discovery |
MalwareDiavol | Diavol can use the ARP table to find remote hosts to scan. |
| T1018 Remote System Discovery |
MalwareBlackCat | BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks. |
| T1018 Remote System Discovery |
MalwareDRATzarus | DRATzarus can search for other machines connected to compromised host and attempt to map the network. |
| T1018 Remote System Discovery |
MalwareSHOTPUT | SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain. |
| T1018 Remote System Discovery |
MalwareFlagpro | Flagpro has been used to execute |
| T1018 Remote System Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments. |
| T1018 Remote System Discovery |
MalwareRemsec | Remsec can ping or traceroute a remote host. |
| T1018 Remote System Discovery |
MalwareSykipot | Sykipot may use |
| T1018 Remote System Discovery |
MalwareEpic | Epic uses the |
| T1018 Remote System Discovery |
MalwareUSBferry | USBferry can use |
| T1018 Remote System Discovery |
MalwareWannaCry | WannaCry scans its local network segment for remote systems to try to exploit and copy itself to. |
| T1018 Remote System Discovery |
MalwareLODEINFO | LODEINFO can run `net view` and `net view /domain` for network discovery. |
| T1018 Remote System Discovery |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE command and execution module can perform target system enumeration. |
| T1018 Remote System Discovery |
MalwareShamoon | Shamoon scans the C-class subnet of the IPs on the victim's interfaces. |
| T1018 Remote System Discovery |
MalwareBlack Basta | Black Basta can use LDAP queries to connect to AD and iterate over connected workstations. |
| T1018 Remote System Discovery |
MalwareBazar | Bazar can enumerate remote systems using |
| T1018 Remote System Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1018 Remote System Discovery |
MalwareMgBot | MgBot includes modules for performing ARP scans of local connected systems. |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1018 Remote System Discovery |
MalwareCarbon | Carbon uses the |
| T1018 Remote System Discovery |
MalwareFunnyDream | FunnyDream can collect information about hosts on the victim network. |
| T1018 Remote System Discovery |
MalwareKwampirs | Kwampirs collects a list of available servers with the command |
| T1018 Remote System Discovery |
MalwarePoetRAT | PoetRAT used Nmap for remote system discovery. |
| T1018 Remote System Discovery |
MalwareKinsing | Kinsing has used a script to parse files like |
| T1018 Remote System Discovery |
MalwarenjRAT | njRAT can identify remote hosts on connected networks. |
| T1018 Remote System Discovery |
MalwareQilin | Qilin can enumerate domain-connected hosts during its discovery phase. |
| T1018 Remote System Discovery |
MalwareIndustroyer | Industroyer can enumerate remote computers in the compromised network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.