Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1016 System Network Configuration Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1016 System Network Configuration Discovery |
GroupScattered Spider | Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1016 System Network Configuration Discovery |
GroupMoses Staff | Moses Staff has collected the domain name of a compromised network. |
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1016 System Network Configuration Discovery |
GroupTropic Trooper | Tropic Trooper has used scripts to collect the host's network topology. |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1016 System Network Configuration Discovery |
GroupAPT1 | APT1 used the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1016 System Network Configuration Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim. |
| T1016 System Network Configuration Discovery |
GroupChimera | Chimera has used ipconfig, Ping, and |
| T1016 System Network Configuration Discovery |
GroupMirrorFace | MirrorFace has used ipconfig for reconnaissance. |
| T1016 System Network Configuration Discovery |
GroupMedusa Group | Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`. |
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1016 System Network Configuration Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1016 System Network Configuration Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1016 System Network Configuration Discovery |
GroupWizard Spider | Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory. |
| T1016 System Network Configuration Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim network configuration. |
| T1016 System Network Configuration Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to enumerate network information. |
| T1016 System Network Configuration Discovery |
GroupHEXANE | |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016 System Network Configuration Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
| T1016 System Network Configuration Discovery |
GroupFIN13 | FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information. |
| T1016 System Network Configuration Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
Malwarecd00r | cd00r can discover the IP for the network interface on the compromised device. |
| T1016 System Network Configuration Discovery |
MalwarePowerDuke | PowerDuke has a command to get the victim's domain and NetBIOS name. |
| T1016 System Network Configuration Discovery |
MalwareEKANS | EKANS can determine the domain of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected the victim machine's local IP address information and MAC address. |
| T1016 System Network Configuration Discovery |
MalwareNinja | Ninja can enumerate the IP address on compromised systems. |
| T1016 System Network Configuration Discovery |
MalwarePikabot | Pikabot gathers victim network information through commands such as |
| T1016 System Network Configuration Discovery |
MalwareAmadey | Amadey can identify the IP address of a victim machine. |
| T1016 System Network Configuration Discovery |
MalwareProxysvc | Proxysvc collects the network adapter information and domain/username information based on current remote sessions. |
| T1016 System Network Configuration Discovery |
MalwareOrz | Orz can gather victim proxy information. |
| T1016 System Network Configuration Discovery |
MalwareTorisma | Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address. |
| T1016 System Network Configuration Discovery |
MalwareNOKKI | NOKKI can gather information on the victim IP address. |
| T1016 System Network Configuration Discovery |
Malwareyty | yty runs |
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1016 System Network Configuration Discovery |
MalwareStuxnet | Stuxnet collects the IP address of a compromised system. |
| T1016 System Network Configuration Discovery |
MalwarePOWRUNER | POWRUNER may collect network configuration data by running |
| T1016 System Network Configuration Discovery |
MalwareKOPILUWAK | KOPILUWAK can use Arp to discover a target's network configuration setttings. |
| T1016 System Network Configuration Discovery |
MalwareSardonic | Sardonic has the ability to execute the `ipconfig` command. |
| T1016 System Network Configuration Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1016 System Network Configuration Discovery |
MalwareKEYMARBLE | KEYMARBLE gathers the MAC address of the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareRedLeaves | RedLeaves can obtain information about network parameters. |
| T1016 System Network Configuration Discovery |
MalwareFelismus | Felismus collects the victim LAN IP address and sends it to the C2 server. |
| T1016 System Network Configuration Discovery |
MalwareGeminiDuke | GeminiDuke collects information on network settings and Internet proxy settings from the victim. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.