ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1049×

61 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
ToolSliver

Sliver can collect network connection information.

T1049
System Network Connections Discovery
ToolPacu

Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering.

T1049
System Network Connections Discovery
ToolEmpire

Empire can enumerate the current network connections of a host.

T1049
System Network Connections Discovery
ToolFRP

FRP can use a dashboard and U/I to display the status of connections from the FRP client and server.

T1049
System Network Connections Discovery
Toolnetstat

netstat can be used to enumerate local network connections, including active TCP connections and other network statistics.

T1049
System Network Connections Discovery
ToolPoshC2

PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections.

T1049
System Network Connections Discovery
Toolnbtstat

nbtstat can be used to discover current NetBIOS sessions.

T1049
System Network Connections Discovery
ToolCrackMapExec

CrackMapExec can discover active sessions for a targeted system.

T1049
System Network Connections Discovery
ToolPupy

Pupy has a built-in utility command for netstat, can do net session through PowerView, and has an interactive shell which can be used to discover additional information.

T1049
System Network Connections Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord.

T1049
System Network Connections Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on network connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.