Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareBlackEnergy | BlackEnergy has gathered information about network IP configurations using ipconfig.exe and about routing tables using route.exe. |
| T1016 System Network Configuration Discovery |
MalwarezwShell | zwShell can obtain the victim IP address. |
| T1016 System Network Configuration Discovery |
MalwareRising Sun | Rising Sun can detect network adapter and IP address information. |
| T1016 System Network Configuration Discovery |
MalwareChrommme | Chrommme can enumerate the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareAvaddon | Avaddon can collect the external IP address of the victim. |
| T1016 System Network Configuration Discovery |
MalwareSocGholish | SocGholish has the ability to enumerate the domain name of a victim, as well as if the host is a member of an Active Directory domain. |
| T1016 System Network Configuration Discovery |
MalwareFlagpro | Flagpro has been used to execute the |
| T1016 System Network Configuration Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the IP of a compromised system. |
| T1016 System Network Configuration Discovery |
MalwareGreen Lambert | Green Lambert can obtain proxy information from a victim's machine using system environment variables. |
| T1016 System Network Configuration Discovery |
MalwareGoldMax | GoldMax retrieved a list of the system's network interface after execution. |
| T1016 System Network Configuration Discovery |
MalwareKeyBoy | KeyBoy can determine the public or WAN IP address for the system. |
| T1016 System Network Configuration Discovery |
MalwareAnchor | Anchor can determine the public IP and location of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareDyre | Dyre has the ability to identify network settings on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareLunarLoader | LunarLoader can verify the targeted host's DNS name which is then used in the creation of a decyrption key. |
| T1016 System Network Configuration Discovery |
MalwarePlugX | PlugX has captured victim IP address details of the targeted machine. |
| T1016 System Network Configuration Discovery |
MalwareReaver | Reaver collects the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareBisonal | Bisonal can execute |
| T1016 System Network Configuration Discovery |
MalwareS-Type | S-Type has used `ipconfig /all` on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareRemsec | Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1016 System Network Configuration Discovery |
MalwareSykipot | Sykipot may use |
| T1016 System Network Configuration Discovery |
MalwareExplosive | Explosive has collected the MAC address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareXbash | Xbash can collect IP addresses and local intranet information from a victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareEpic | Epic uses the |
| T1016 System Network Configuration Discovery |
MalwareLightNeuron | LightNeuron gathers information about network adapters using the Win32 API call |
| T1016 System Network Configuration Discovery |
MalwareCuba | Cuba can retrieve the ARP cache from the local system by using |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1016 System Network Configuration Discovery |
MalwareNanHaiShu | NanHaiShu can gather information about the victim proxy server. |
| T1016 System Network Configuration Discovery |
MalwareNGLite | NGLite identifies the victim system MAC and IPv4 addresses and uses these to establish a victim identifier. |
| T1016 System Network Configuration Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines. |
| T1016 System Network Configuration Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the domain of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command. |
| T1016 System Network Configuration Discovery |
MalwareElise | Elise executes |
| T1016 System Network Configuration Discovery |
MalwareUSBferry | USBferry can detect the infected machine's network topology using |
| T1016 System Network Configuration Discovery |
MalwareWannaCry | WannaCry will attempt to determine the local network segment it is a part of. |
| T1016 System Network Configuration Discovery |
MalwareTSCookie | TSCookie has the ability to identify the IP of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareLatrodectus | Latrodectus can discover the IP and MAC address of a targeted host. |
| T1016 System Network Configuration Discovery |
MalwareSaint Bot | Saint Bot can collect the IP address of a victim machine. |
| T1016 System Network Configuration Discovery |
MalwarePay2Key | Pay2Key can identify the IP and MAC addresses of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareLODEINFO | LODEINFO can enumerate the MAC address of the compromised host. |
| T1016 System Network Configuration Discovery |
MalwareCharmPower | CharmPower has the ability to use |
| T1016 System Network Configuration Discovery |
MalwareQUADAGENT | QUADAGENT gathers the current domain the victim system belongs to. |
| T1016 System Network Configuration Discovery |
MalwareSagerunex | Sagerunex will gather system information such as MAC and IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareSys10 | Sys10 collects the local IP address of the victim and sends it to the C2. |
| T1016 System Network Configuration Discovery |
MalwareRoyal | Royal can enumerate IP addresses using `GetIpAddrTable`. |
| T1016 System Network Configuration Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information on the network configuration of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBandook | Bandook has a command to get the public IP address from a system. |
| T1016 System Network Configuration Discovery |
MalwarePipeMon | PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon. |
| T1016 System Network Configuration Discovery |
MalwareMagicRAT | MagicRAT collects system network information using commands such as `ipconfig /all`. |
| T1016 System Network Configuration Discovery |
MalwareKONNI | KONNI can collect the IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareT9000 | T9000 gathers and beacons the MAC and IP addresses during installation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.