Real-world descriptions of how a group, tool or campaign used a technique.
1146 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers victim IP information during initial installation stages. |
| T1016 System Network Configuration Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system. |
| T1016 System Network Configuration Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details. |
| T1016 System Network Configuration Discovery |
CampaignC0018 | During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network. |
| T1016 System Network Configuration Discovery |
CampaignShadowRay | During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses. |
| T1016 System Network Configuration Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary configured Claude Code to identify and gather system configurations of discovered devices. |
| T1016 System Network Configuration Discovery |
CampaignC0015 | During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host. |
| T1016 System Network Configuration Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments. |
| T1016 System Network Configuration Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used ipconfig for discovery on remote systems. |
| T1016 System Network Configuration Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands. |
| T1016 System Network Configuration Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands. |
| T1016 System Network Configuration Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local network configuration with `ipconfig`. |
| T1016 System Network Configuration Discovery |
CampaignC0017 | During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery. |
| T1016.001 Internet Connection Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
| T1016.001 Internet Connection Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity. |
| T1016.002 Wi-Fi Discovery |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system. |
| T1018 Remote System Discovery |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets. |
| T1018 Remote System Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1018 Remote System Discovery |
CampaignC0015 | During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| T1018 Remote System Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1018 Remote System Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| T1018 Remote System Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance. |
| T1018 Remote System Discovery |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
| T1018 Remote System Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory. |
| T1018 Remote System Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions. |
| T1020 Automated Exfiltration |
CampaignFrankenstein | During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2. |
| T1020 Automated Exfiltration |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors used API queries to automatically exfiltrate large volumes of data. |
| T1020 Automated Exfiltration |
CampaignArcaneDoor | ArcaneDoor included scripted exfiltration of collected data. |
| T1021.001 Remote Desktop Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement. |
| T1021.001 Remote Desktop Protocol |
CampaignC0018 | During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892. |
| T1021.001 Remote Desktop Protocol |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1021.001 Remote Desktop Protocol |
CampaignC0015 | During C0015, the threat actors used RDP to access specific network hosts of interest. |
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.001 Remote Desktop Protocol |
CampaignC0032 | During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| T1021.001 Remote Desktop Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.001 Remote Desktop Protocol |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks. |
| T1021.002 SMB/Windows Admin Shares |
CampaignCutting Edge | During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB. |
| T1021.002 SMB/Windows Admin Shares |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
| T1021.002 SMB/Windows Admin Shares |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally. |
| T1021.002 SMB/Windows Admin Shares |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation Wocao | During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
CampaignLeviathan Australian Intrusions | Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions. |
| T1021.004 SSH |
CampaignCutting Edge | During Cutting Edge, threat actors used SSH for lateral movement. |
| T1021.004 SSH |
CampaignC0032 | During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution. |
| T1021.004 SSH |
CampaignLeviathan Australian Intrusions | Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions. |
| T1021.006 Windows Remote Management |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks. |
| T1021.006 Windows Remote Management |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.