ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareHavoc

Havoc has a module for network enumeration including determining IP addresses.

T1016
System Network Configuration Discovery
MalwareGravityRAT

GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.

T1016
System Network Configuration Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the local IP address, and external IP.

T1016
System Network Configuration Discovery
MalwareStrongPity

StrongPity can identify the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwarexCaon

xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address.

T1016
System Network Configuration Discovery
MalwarePLAINTEE

PLAINTEE uses the ipconfig /all command to gather the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareOceanSalt

OceanSalt can collect the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareBrave Prince

Brave Prince gathers network configuration information as well as the ARP cache.

T1016
System Network Configuration Discovery
MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareJ-magic

J-magic can compare the host and remote IPs to check if a received packet is from the infected machine.

T1016
System Network Configuration Discovery
MalwareiKitten

iKitten will look for the current IP address.

T1016
System Network Configuration Discovery
MalwareGomir

Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses.

T1016
System Network Configuration Discovery
MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1016
System Network Configuration Discovery
MalwareOlympic Destroyer

Olympic Destroyer uses API calls to enumerate the infected system's ARP table.

T1016
System Network Configuration Discovery
MalwareBOLDMOVE

BOLDMOVE enumerates network interfaces on the infected host.

T1016
System Network Configuration Discovery
MalwareCrimson

Crimson contains a command to collect the victim MAC address and LAN IP.

T1016
System Network Configuration Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate infected system network information.

T1016
System Network Configuration Discovery
MalwareTurian

Turian can retrieve the internal IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareMachete

Machete collects the MAC address of the target computer and other network configuration information.

T1016
System Network Configuration Discovery
MalwareAction RAT

Action RAT has the ability to collect the MAC address of an infected host.

T1016
System Network Configuration Discovery
MalwareAvenger

Avenger can identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about its IP addresses and MAC addresses.

T1016
System Network Configuration Discovery
MalwarePUBLOAD

PUBLOAD has obtained information about local networks through the `ipconfig /all` command.

T1016
System Network Configuration Discovery
MalwareGootloader

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1016
System Network Configuration Discovery
MalwarePingPull

PingPull can retrieve the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareWellMess

WellMess can identify the IP address and user domain on the target machine.

T1016
System Network Configuration Discovery
MalwareWoody RAT

Woody RAT can retrieve network interface and proxy information.

T1016
System Network Configuration Discovery
MalwareMafalda

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.

T1016
System Network Configuration Discovery
MalwareSquirrelwaffle

Squirrelwaffle has collected the victim’s external IP address.

T1016
System Network Configuration Discovery
MalwareHexEval Loader

HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host.

T1016
System Network Configuration Discovery
MalwareShrinkLocker

ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption.

T1016
System Network Configuration Discovery
MalwareAgent.btz

Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file.

T1016
System Network Configuration Discovery
MalwareRifdoor

Rifdoor has the ability to identify the IP address of the compromised host.

T1016
System Network Configuration Discovery
MalwareInvisiMole

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1016
System Network Configuration Discovery
MalwareNaid

Naid collects the domain name from a compromised host.

T1016
System Network Configuration Discovery
MalwareVolgmer

Volgmer can gather the IP address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareZeroT

ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server.

T1016
System Network Configuration Discovery
MalwareOkrum

Okrum can collect network information, including the host IP address, DNS, and proxy information.

T1016
System Network Configuration Discovery
MalwareBonadan

Bonadan can find the external IP address of the infected host.

T1016
System Network Configuration Discovery
MalwareNeoichor

Neoichor can gather the IP address from an infected host.

T1016
System Network Configuration Discovery
MalwareConti

Conti can retrieve the ARP cache from the local system by using the GetIpNetTable() API call and check to ensure IP addresses it connects to are for local, non-Internet, systems.

T1016
System Network Configuration Discovery
MalwareDiavol

Diavol can enumerate victims' local and external IPs when registering with C2.

T1016
System Network Configuration Discovery
MalwareIcedID

IcedID used the `ipconfig /all` command and a batch script to gather network information.

T1016
System Network Configuration Discovery
MalwareVERMIN

VERMIN gathers the local IP address.

T1016
System Network Configuration Discovery
MalwareNightdoor

Nightdoor gathers information on victim system network configuration such as MAC addresses.

T1016
System Network Configuration Discovery
MalwarePowerShower

PowerShower has the ability to identify the current Windows domain of the infected host.

T1016
System Network Configuration Discovery
MalwareKazuar

Kazuar gathers information about network adapters.

T1016
System Network Configuration Discovery
MalwareFatDuke

FatDuke can identify the MAC address on the target computer.

T1016
System Network Configuration Discovery
MalwareLucifer

Lucifer can collect the IP address of a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.