ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe.

T1016
System Network Configuration Discovery
MalwarezwShell

zwShell can obtain the victim IP address.

T1016
System Network Configuration Discovery
MalwareRising Sun

Rising Sun can detect network adapter and IP address information.

T1016
System Network Configuration Discovery
MalwareChrommme

Chrommme can enumerate the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareAvaddon

Avaddon can collect the external IP address of the victim.

T1016
System Network Configuration Discovery
MalwareSocGholish

SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain.

T1016
System Network Configuration Discovery
MalwareFlagpro

Flagpro has been used to execute the ipconfig /all command on a victim system.

T1016
System Network Configuration Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the IP of a compromised system.

T1016
System Network Configuration Discovery
MalwareGreen Lambert

Green Lambert can obtain proxy information from a victim's machine using system environment variables.

T1016
System Network Configuration Discovery
MalwareGoldMax

GoldMax retrieved a list of the system's network interface after execution.

T1016
System Network Configuration Discovery
MalwareKeyBoy

KeyBoy can determine the public or WAN IP address for the system.

T1016
System Network Configuration Discovery
MalwareAnchor

Anchor can determine the public IP and location of a compromised host.

T1016
System Network Configuration Discovery
MalwareDyre

Dyre has the ability to identify network settings on a compromised host.

T1016
System Network Configuration Discovery
MalwareLunarLoader

LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key.

T1016
System Network Configuration Discovery
MalwarePlugX

PlugX has captured victim IP address details of the targeted machine.

T1016
System Network Configuration Discovery
MalwareReaver

Reaver collects the victim's IP address.

T1016
System Network Configuration Discovery
MalwareBisonal

Bisonal can execute ipconfig on the victim’s machine.

T1016
System Network Configuration Discovery
MalwareS-Type

S-Type has used `ipconfig /all` on a compromised host.

T1016
System Network Configuration Discovery
MalwareRemsec

Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache.

T1016
System Network Configuration Discovery
MalwareSykipot

Sykipot may use ipconfig /all to gather system network configuration details.

T1016
System Network Configuration Discovery
MalwareExplosive

Explosive has collected the MAC address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareXbash

Xbash can collect IP addresses and local intranet information from a victim’s machine.

T1016
System Network Configuration Discovery
MalwareEpic

Epic uses the nbtstat -n and nbtstat -s commands on the victim’s machine.

T1016
System Network Configuration Discovery
MalwareLightNeuron

LightNeuron gathers information about network adapters using the Win32 API call GetAdaptersInfo.

T1016
System Network Configuration Discovery
MalwareCuba

Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.

T1016
System Network Configuration Discovery
MalwareClambling

Clambling can enumerate the IP address of a compromised machine.

T1016
System Network Configuration Discovery
MalwareNanHaiShu

NanHaiShu can gather information about the victim proxy server.

T1016
System Network Configuration Discovery
MalwareNGLite

NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier.

T1016
System Network Configuration Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.

T1016
System Network Configuration Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the domain of the compromised host.

T1016
System Network Configuration Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command.

T1016
System Network Configuration Discovery
MalwareElise

Elise executes ipconfig /all after initial communication is made to the remote server.

T1016
System Network Configuration Discovery
MalwareUSBferry

USBferry can detect the infected machine's network topology using ipconfig and arp.

T1016
System Network Configuration Discovery
MalwareWannaCry

WannaCry will attempt to determine the local network segment it is a part of.

T1016
System Network Configuration Discovery
MalwareTSCookie

TSCookie has the ability to identify the IP of the infected host.

T1016
System Network Configuration Discovery
MalwareLatrodectus

Latrodectus can discover the IP and MAC address of a targeted host.

T1016
System Network Configuration Discovery
MalwareSaint Bot

Saint Bot can collect the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwarePay2Key

Pay2Key can identify the IP and MAC addresses of the compromised host.

T1016
System Network Configuration Discovery
MalwareLODEINFO

LODEINFO can enumerate the MAC address of the compromised host.

T1016
System Network Configuration Discovery
MalwareCharmPower

CharmPower has the ability to use ipconfig to enumerate system network settings.

T1016
System Network Configuration Discovery
MalwareQUADAGENT

QUADAGENT gathers the current domain the victim system belongs to.

T1016
System Network Configuration Discovery
MalwareSagerunex

Sagerunex will gather system information such as MAC and IP addresses.

T1016
System Network Configuration Discovery
MalwareSys10

Sys10 collects the local IP address of the victim and sends it to the C2.

T1016
System Network Configuration Discovery
MalwareRoyal

Royal can enumerate IP addresses using `GetIpAddrTable`.

T1016
System Network Configuration Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information on the network configuration of a compromised host.

T1016
System Network Configuration Discovery
MalwareBandook

Bandook has a command to get the public IP address from a system.

T1016
System Network Configuration Discovery
MalwarePipeMon

PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon.

T1016
System Network Configuration Discovery
MalwareMagicRAT

MagicRAT collects system network information using commands such as `ipconfig /all`.

T1016
System Network Configuration Discovery
MalwareKONNI

KONNI can collect the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareT9000

T9000 gathers and beacons the MAC and IP addresses during installation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.