ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShamoon

Shamoon obtains the target's IP address and local network segment.

T1016
System Network Configuration Discovery
MalwareJHUHUGIT

A JHUHUGIT variant gathers network interface card information.

T1016
System Network Configuration Discovery
MalwareBLUELIGHT

BLUELIGHT can collect IP information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwaredown_new

down_new has the ability to identify the MAC address of a compromised host.

T1016
System Network Configuration Discovery
MalwareIxeshe

Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system.

T1016
System Network Configuration Discovery
MalwareRedLine Stealer

RedLine Stealer can enumeate information about victims’ systems including IP addresses.

T1016
System Network Configuration Discovery
MalwareCatchamas

Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRogueRobin

RogueRobin gathers the IP address and domain from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareBoxCaon

BoxCaon can collect the victim's MAC address by using the GetAdaptersInfo API.

T1016
System Network Configuration Discovery
MalwareSDBbot

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1016
System Network Configuration Discovery
MalwareMosquito

Mosquito uses the ipconfig command.

T1016
System Network Configuration Discovery
MalwareQUIETCANARY

QUIETCANARY can identify the default proxy setting on a compromised host.

T1016
System Network Configuration Discovery
MalwareGrandoreiro

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.

T1016
System Network Configuration Discovery
MalwareWellMail

WellMail can identify the IP address of the victim system.

T1016
System Network Configuration Discovery
MalwareLiteDuke

LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera.

T1016
System Network Configuration Discovery
MalwareSibot

Sibot checked if the compromised system is configured to use proxies.

T1016
System Network Configuration Discovery
MalwareBazar

Bazar can collect the IP address and NetBIOS name of an infected machine.

T1016
System Network Configuration Discovery
MalwareKobalos

Kobalos can record the IP address of the target machine.

T1016
System Network Configuration Discovery
MalwareRATANKBA

RATANKBA gathers the victim’s IP address via the ipconfig -all command.

T1016
System Network Configuration Discovery
MalwareBADCALL

BADCALL collects the network adapter information.

T1016
System Network Configuration Discovery
MalwareMoonWind

MoonWind obtains the victim IP address.

T1016
System Network Configuration Discovery
MalwareRyuk

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1016
System Network Configuration Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced IP Scanner tool.

T1016
System Network Configuration Discovery
MalwareZebrocy

Zebrocy runs the ipconfig /all command.

T1016
System Network Configuration Discovery
MalwareSpeakUp

SpeakUp uses the ifconfig -a command.

T1016
System Network Configuration Discovery
MalwareCobalt Strike

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1016
System Network Configuration Discovery
MalwareSUNBURST

SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information.

T1016
System Network Configuration Discovery
MalwareHotCroissant

HotCroissant has the ability to identify the IP address of the compromised machine.

T1016
System Network Configuration Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim's IP address.

T1016
System Network Configuration Discovery
MalwareValak

Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine.

T1016
System Network Configuration Discovery
MalwareMilan

Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings.

T1016
System Network Configuration Discovery
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host.

T1016
System Network Configuration Discovery
MalwareTaidoor

Taidoor has collected the MAC address of a compromised host; it can also use GetAdaptersInfo to identify network adapters.

T1016
System Network Configuration Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names.

T1016
System Network Configuration Discovery
MalwareNanoCore

NanoCore gathers the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareTajMahal

TajMahal has the ability to identify the MAC address on an infected host.

T1016
System Network Configuration Discovery
MalwareCarbon

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1016
System Network Configuration Discovery
MalwareCalisto

Calisto runs the ifconfig command to obtain the IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwarePisloader

Pisloader has a command to collect the victim's IP address.

T1016
System Network Configuration Discovery
MalwareRamsay

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.

T1016
System Network Configuration Discovery
MalwareRevenge RAT

Revenge RAT collects the IP address and MAC address from the system.

T1016
System Network Configuration Discovery
MalwareMacMa

MacMa can collect IP addresses from a compromised host.

T1016
System Network Configuration Discovery
MalwareFunnyDream

FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.

T1016
System Network Configuration Discovery
MalwareMore_eggs

More_eggs has the capability to gather the IP address from the victim's machine.

T1016
System Network Configuration Discovery
MalwareSysUpdate

SysUpdate can collected the IP address and domain name of a compromised host.

T1016
System Network Configuration Discovery
MalwareKwampirs

Kwampirs collects network adapter and interface information by using the commands ipconfig /all, arp -a and route print. It also collects the system's MAC address with getmac and domain configuration with net config workstation.

T1016
System Network Configuration Discovery
MalwareDEADEYE

DEADEYE can discover the DNS domain name of a targeted system.

T1016
System Network Configuration Discovery
MalwareLAMEHUG

LAMEHUG can enumerate network information on compromised hosts.

T1016
System Network Configuration Discovery
MalwareKessel

Kessel has collected the DNS address of the infected host.

T1016
System Network Configuration Discovery
MalwareGrimAgent

GrimAgent can enumerate the IP and domain of a target system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.