Real-world descriptions of how a group, tool or campaign used a technique.
61 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
ToolSliver | Sliver can collect network connection information. |
| T1049 System Network Connections Discovery |
ToolPacu | Once inside a Virtual Private Cloud, Pacu can attempt to identify DirectConnect, VPN, or VPC Peering. |
| T1049 System Network Connections Discovery |
ToolEmpire | Empire can enumerate the current network connections of a host. |
| T1049 System Network Connections Discovery |
ToolFRP | FRP can use a dashboard and U/I to display the status of connections from the FRP client and server. |
| T1049 System Network Connections Discovery |
Toolnetstat | netstat can be used to enumerate local network connections, including active TCP connections and other network statistics. |
| T1049 System Network Connections Discovery |
ToolPoshC2 | PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections. |
| T1049 System Network Connections Discovery |
Toolnbtstat | nbtstat can be used to discover current NetBIOS sessions. |
| T1049 System Network Connections Discovery |
ToolCrackMapExec | CrackMapExec can discover active sessions for a targeted system. |
| T1049 System Network Connections Discovery |
ToolPupy | Pupy has a built-in utility command for |
| T1049 System Network Connections Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1049 System Network Connections Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on network connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.