Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareHavoc | Havoc has a module for network enumeration including determining IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareGravityRAT | GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name. |
| T1016 System Network Configuration Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the local IP address, and external IP. |
| T1016 System Network Configuration Discovery |
MalwareStrongPity | StrongPity can identify the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwarexCaon | xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address. |
| T1016 System Network Configuration Discovery |
MalwarePLAINTEE | PLAINTEE uses the |
| T1016 System Network Configuration Discovery |
MalwareOceanSalt | OceanSalt can collect the victim’s IP address. |
| T1016 System Network Configuration Discovery |
MalwareBrave Prince | Brave Prince gathers network configuration information as well as the ARP cache. |
| T1016 System Network Configuration Discovery |
MalwareAppleSeed | AppleSeed can identify the IP of a targeted system. |
| T1016 System Network Configuration Discovery |
MalwareNETWIRE | NETWIRE can collect the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareJ-magic | J-magic can compare the host and remote IPs to check if a received packet is from the infected machine. |
| T1016 System Network Configuration Discovery |
MalwareiKitten | iKitten will look for the current IP address. |
| T1016 System Network Configuration Discovery |
MalwareGomir | Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses. |
| T1016 System Network Configuration Discovery |
MalwareAria-body | Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses API calls to enumerate the infected system's ARP table. |
| T1016 System Network Configuration Discovery |
MalwareBOLDMOVE | BOLDMOVE enumerates network interfaces on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareCrimson | Crimson contains a command to collect the victim MAC address and LAN IP. |
| T1016 System Network Configuration Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate infected system network information. |
| T1016 System Network Configuration Discovery |
MalwareTurian | Turian can retrieve the internal IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMachete | Machete collects the MAC address of the target computer and other network configuration information. |
| T1016 System Network Configuration Discovery |
MalwareAction RAT | Action RAT has the ability to collect the MAC address of an infected host. |
| T1016 System Network Configuration Discovery |
MalwareAvenger | Avenger can identify the domain of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about its IP addresses and MAC addresses. |
| T1016 System Network Configuration Discovery |
MalwarePUBLOAD | PUBLOAD has obtained information about local networks through the `ipconfig /all` command. |
| T1016 System Network Configuration Discovery |
MalwareGootloader | Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites. |
| T1016 System Network Configuration Discovery |
MalwarePingPull | PingPull can retrieve the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareWellMess | WellMess can identify the IP address and user domain on the target machine. |
| T1016 System Network Configuration Discovery |
MalwareWoody RAT | Woody RAT can retrieve network interface and proxy information. |
| T1016 System Network Configuration Discovery |
MalwareMafalda | Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table. |
| T1016 System Network Configuration Discovery |
MalwareSquirrelwaffle | Squirrelwaffle has collected the victim’s external IP address. |
| T1016 System Network Configuration Discovery |
MalwareHexEval Loader | HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host. |
| T1016 System Network Configuration Discovery |
MalwareShrinkLocker | ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption. |
| T1016 System Network Configuration Discovery |
MalwareAgent.btz | Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file. |
| T1016 System Network Configuration Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the IP address of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareInvisiMole | InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1016 System Network Configuration Discovery |
MalwareNaid | Naid collects the domain name from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareVolgmer | Volgmer can gather the IP address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareZeroT | ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server. |
| T1016 System Network Configuration Discovery |
MalwareOkrum | Okrum can collect network information, including the host IP address, DNS, and proxy information. |
| T1016 System Network Configuration Discovery |
MalwareBonadan | Bonadan can find the external IP address of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareNeoichor | Neoichor can gather the IP address from an infected host. |
| T1016 System Network Configuration Discovery |
MalwareConti | Conti can retrieve the ARP cache from the local system by using the |
| T1016 System Network Configuration Discovery |
MalwareDiavol | Diavol can enumerate victims' local and external IPs when registering with C2. |
| T1016 System Network Configuration Discovery |
MalwareIcedID | IcedID used the `ipconfig /all` command and a batch script to gather network information. |
| T1016 System Network Configuration Discovery |
MalwareVERMIN | VERMIN gathers the local IP address. |
| T1016 System Network Configuration Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system network configuration such as MAC addresses. |
| T1016 System Network Configuration Discovery |
MalwarePowerShower | PowerShower has the ability to identify the current Windows domain of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareKazuar | Kazuar gathers information about network adapters. |
| T1016 System Network Configuration Discovery |
MalwareFatDuke | FatDuke can identify the MAC address on the target computer. |
| T1016 System Network Configuration Discovery |
MalwareLucifer | Lucifer can collect the IP address of a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.