ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupMustang Panda

Mustang Panda has used ipconfig and arp to determine network configuration information. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1016
System Network Configuration Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.

T1016
System Network Configuration Discovery
GroupScattered Spider

Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`.

T1016
System Network Configuration Discovery
GroupMoses Staff

Moses Staff has collected the domain name of a compromised network.

T1016
System Network Configuration Discovery
GroupOilRig

OilRig has run ipconfig /all on a victim.

T1016
System Network Configuration Discovery
GroupHigaisa

Higaisa used ipconfig to gather network configuration information.

T1016
System Network Configuration Discovery
GroupTropic Trooper

Tropic Trooper has used scripts to collect the host's network topology.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1016
System Network Configuration Discovery
GroupAPT1

APT1 used the ipconfig /all command to gather network configuration information.

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1016
System Network Configuration Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts.

T1016
System Network Configuration Discovery
GroupStealth Falcon

Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim.

T1016
System Network Configuration Discovery
GroupChimera

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.

T1016
System Network Configuration Discovery
GroupMirrorFace

MirrorFace has used ipconfig for reconnaissance.

T1016
System Network Configuration Discovery
GroupMedusa Group

Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.

T1016
System Network Configuration Discovery
GroupDarkhotel

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1016
System Network Configuration Discovery
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information.

T1016
System Network Configuration Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.

T1016
System Network Configuration Discovery
GroupEarth Lusca

Earth Lusca used the command ipconfig to obtain information about network configurations.

T1016
System Network Configuration Discovery
GroupWizard Spider

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.

T1016
System Network Configuration Discovery
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim network configuration.

T1016
System Network Configuration Discovery
GroupPlay

Play has used the information-stealing tool Grixba to enumerate network information.

T1016
System Network Configuration Discovery
GroupHEXANE

HEXANE has used Ping and `tracert` for network discovery.

T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1016
System Network Configuration Discovery
GroupThreat Group-3390

Threat Group-3390 actors use NBTscan to discover vulnerable systems.

T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016
System Network Configuration Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwarecd00r

cd00r can discover the IP for the network interface on the compromised device.

T1016
System Network Configuration Discovery
MalwarePowerDuke

PowerDuke has a command to get the victim's domain and NetBIOS name.

T1016
System Network Configuration Discovery
MalwareEKANS

EKANS can determine the domain of a compromised host.

T1016
System Network Configuration Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected the victim machine's local IP address information and MAC address.

T1016
System Network Configuration Discovery
MalwareNinja

Ninja can enumerate the IP address on compromised systems.

T1016
System Network Configuration Discovery
MalwarePikabot

Pikabot gathers victim network information through commands such as ipconfig and ipconfig /all.

T1016
System Network Configuration Discovery
MalwareAmadey

Amadey can identify the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwareProxysvc

Proxysvc collects the network adapter information and domain/username information based on current remote sessions.

T1016
System Network Configuration Discovery
MalwareOrz

Orz can gather victim proxy information.

T1016
System Network Configuration Discovery
MalwareTorisma

Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address.

T1016
System Network Configuration Discovery
MalwareNOKKI

NOKKI can gather information on the victim IP address.

T1016
System Network Configuration Discovery
Malwareyty

yty runs ipconfig /all and collects the domain name.

T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1016
System Network Configuration Discovery
MalwareStuxnet

Stuxnet collects the IP address of a compromised system.

T1016
System Network Configuration Discovery
MalwarePOWRUNER

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1016
System Network Configuration Discovery
MalwareKOPILUWAK

KOPILUWAK can use Arp to discover a target's network configuration setttings.

T1016
System Network Configuration Discovery
MalwareSardonic

Sardonic has the ability to execute the `ipconfig` command.

T1016
System Network Configuration Discovery
MalwareEmissary

Emissary has the capability to execute the command ipconfig /all.

T1016
System Network Configuration Discovery
MalwareKEYMARBLE

KEYMARBLE gathers the MAC address of the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRedLeaves

RedLeaves can obtain information about network parameters.

T1016
System Network Configuration Discovery
MalwareFelismus

Felismus collects the victim LAN IP address and sends it to the C2 server.

T1016
System Network Configuration Discovery
MalwareGeminiDuke

GeminiDuke collects information on network settings and Internet proxy settings from the victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.