Real-world descriptions of how a group, tool or campaign used a technique.
232 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareWoody RAT | Woody RAT can retrieve network interface and proxy information. |
| T1016 System Network Configuration Discovery |
MalwareMafalda | Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table. |
| T1016 System Network Configuration Discovery |
MalwareSquirrelwaffle | Squirrelwaffle has collected the victim’s external IP address. |
| T1016 System Network Configuration Discovery |
MalwareHexEval Loader | HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host. |
| T1016 System Network Configuration Discovery |
MalwareShrinkLocker | ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption. |
| T1016 System Network Configuration Discovery |
MalwareAgent.btz | Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file. |
| T1016 System Network Configuration Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the IP address of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareInvisiMole | InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1016 System Network Configuration Discovery |
MalwareNaid | Naid collects the domain name from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareVolgmer | Volgmer can gather the IP address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareZeroT | ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server. |
| T1016 System Network Configuration Discovery |
MalwareOkrum | Okrum can collect network information, including the host IP address, DNS, and proxy information. |
| T1016 System Network Configuration Discovery |
MalwareBonadan | Bonadan can find the external IP address of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareNeoichor | Neoichor can gather the IP address from an infected host. |
| T1016 System Network Configuration Discovery |
MalwareConti | Conti can retrieve the ARP cache from the local system by using the |
| T1016 System Network Configuration Discovery |
MalwareDiavol | Diavol can enumerate victims' local and external IPs when registering with C2. |
| T1016 System Network Configuration Discovery |
MalwareIcedID | IcedID used the `ipconfig /all` command and a batch script to gather network information. |
| T1016 System Network Configuration Discovery |
MalwareVERMIN | VERMIN gathers the local IP address. |
| T1016 System Network Configuration Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system network configuration such as MAC addresses. |
| T1016 System Network Configuration Discovery |
MalwarePowerShower | PowerShower has the ability to identify the current Windows domain of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareKazuar | Kazuar gathers information about network adapters. |
| T1016 System Network Configuration Discovery |
MalwareFatDuke | FatDuke can identify the MAC address on the target computer. |
| T1016 System Network Configuration Discovery |
MalwareLucifer | Lucifer can collect the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe. |
| T1016 System Network Configuration Discovery |
MalwarezwShell | zwShell can obtain the victim IP address. |
| T1016 System Network Configuration Discovery |
MalwareRising Sun | Rising Sun can detect network adapter and IP address information. |
| T1016 System Network Configuration Discovery |
MalwareChrommme | Chrommme can enumerate the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareAvaddon | Avaddon can collect the external IP address of the victim. |
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1016 System Network Configuration Discovery |
MalwareFlagpro | Flagpro has been used to execute the |
| T1016 System Network Configuration Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the IP of a compromised system. |
| T1016 System Network Configuration Discovery |
MalwareGreen Lambert | Green Lambert can obtain proxy information from a victim's machine using system environment variables. |
| T1016 System Network Configuration Discovery |
MalwareGoldMax | GoldMax retrieved a list of the system's network interface after execution. |
| T1016 System Network Configuration Discovery |
MalwareKeyBoy | KeyBoy can determine the public or WAN IP address for the system. |
| T1016 System Network Configuration Discovery |
MalwareAnchor | Anchor can determine the public IP and location of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareDyre | Dyre has the ability to identify network settings on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareLunarLoader | LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key. |
| T1016 System Network Configuration Discovery |
MalwarePlugX | PlugX has captured victim IP address details of the targeted machine. |
| T1016 System Network Configuration Discovery |
MalwareReaver | Reaver collects the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1016 System Network Configuration Discovery |
MalwareS-Type | S-Type has used `ipconfig /all` on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareRemsec | Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1016 System Network Configuration Discovery |
MalwareSykipot | Sykipot may use |
| T1016 System Network Configuration Discovery |
MalwareExplosive | Explosive has collected the MAC address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareXbash | Xbash can collect IP addresses and local intranet information from a victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareEpic | Epic uses the |
| T1016 System Network Configuration Discovery |
MalwareLightNeuron | LightNeuron gathers information about network adapters using the Win32 API call |
| T1016 System Network Configuration Discovery |
MalwareCuba | Cuba can retrieve the ARP cache from the local system by using |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1016 System Network Configuration Discovery |
MalwareNanHaiShu | NanHaiShu can gather information about the victim proxy server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.