Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareShamoon | Shamoon obtains the target's IP address and local network segment. |
| T1016 System Network Configuration Discovery |
MalwareJHUHUGIT | A JHUHUGIT variant gathers network interface card information. |
| T1016 System Network Configuration Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect IP information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
Malwaredown_new | down_new has the ability to identify the MAC address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareIxeshe | Ixeshe enumerates the IP address, network proxy settings, and domain name from a victim's system. |
| T1016 System Network Configuration Discovery |
MalwareRedLine Stealer | RedLine Stealer can enumeate information about victims’ systems including IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareCatchamas | Catchamas gathers the Mac address, IP address, and the network adapter information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareRogueRobin | RogueRobin gathers the IP address and domain from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareBoxCaon | BoxCaon can collect the victim's MAC address by using the |
| T1016 System Network Configuration Discovery |
MalwareSDBbot | SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMosquito | Mosquito uses the |
| T1016 System Network Configuration Discovery |
MalwareQUIETCANARY | QUIETCANARY can identify the default proxy setting on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareGrandoreiro | Grandoreiro can determine the IP and physical location of the compromised host via IPinfo. |
| T1016 System Network Configuration Discovery |
MalwareWellMail | WellMail can identify the IP address of the victim system. |
| T1016 System Network Configuration Discovery |
MalwareLiteDuke | LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera. |
| T1016 System Network Configuration Discovery |
MalwareSibot | Sibot checked if the compromised system is configured to use proxies. |
| T1016 System Network Configuration Discovery |
MalwareBazar | Bazar can collect the IP address and NetBIOS name of an infected machine. |
| T1016 System Network Configuration Discovery |
MalwareKobalos | Kobalos can record the IP address of the target machine. |
| T1016 System Network Configuration Discovery |
MalwareRATANKBA | RATANKBA gathers the victim’s IP address via the |
| T1016 System Network Configuration Discovery |
MalwareBADCALL | BADCALL collects the network adapter information. |
| T1016 System Network Configuration Discovery |
MalwareMoonWind | MoonWind obtains the victim IP address. |
| T1016 System Network Configuration Discovery |
MalwareRyuk | Ryuk has called |
| T1016 System Network Configuration Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced IP Scanner tool. |
| T1016 System Network Configuration Discovery |
MalwareZebrocy | Zebrocy runs the |
| T1016 System Network Configuration Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1016 System Network Configuration Discovery |
MalwareCobalt Strike | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1016 System Network Configuration Discovery |
MalwareSUNBURST | SUNBURST collected all network interface MAC addresses that are up and not loopback devices, as well as IP address, DHCP configuration, and domain information. |
| T1016 System Network Configuration Discovery |
MalwareHotCroissant | HotCroissant has the ability to identify the IP address of the compromised machine. |
| T1016 System Network Configuration Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareValak | Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine. |
| T1016 System Network Configuration Discovery |
MalwareMilan | Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings. |
| T1016 System Network Configuration Discovery |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can collect the network interface MAC address on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareTaidoor | Taidoor has collected the MAC address of a compromised host; it can also use |
| T1016 System Network Configuration Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `if_nameindex` to gather network interface names. |
| T1016 System Network Configuration Discovery |
MalwareNanoCore | NanoCore gathers the IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareTajMahal | TajMahal has the ability to identify the MAC address on an infected host. |
| T1016 System Network Configuration Discovery |
MalwareCarbon | Carbon can collect the IP address of the victims and other computers on the network using the commands: |
| T1016 System Network Configuration Discovery |
MalwareCalisto | Calisto runs the |
| T1016 System Network Configuration Discovery |
MalwarePisloader | Pisloader has a command to collect the victim's IP address. |
| T1016 System Network Configuration Discovery |
MalwareRamsay | Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables. |
| T1016 System Network Configuration Discovery |
MalwareRevenge RAT | Revenge RAT collects the IP address and MAC address from the system. |
| T1016 System Network Configuration Discovery |
MalwareMacMa | MacMa can collect IP addresses from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareFunnyDream | FunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies. |
| T1016 System Network Configuration Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the IP address from the victim's machine. |
| T1016 System Network Configuration Discovery |
MalwareSysUpdate | SysUpdate can collected the IP address and domain name of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareKwampirs | Kwampirs collects network adapter and interface information by using the commands |
| T1016 System Network Configuration Discovery |
MalwareDEADEYE | DEADEYE can discover the DNS domain name of a targeted system. |
| T1016 System Network Configuration Discovery |
MalwareLAMEHUG | LAMEHUG can enumerate network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwareKessel | Kessel has collected the DNS address of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareGrimAgent | GrimAgent can enumerate the IP and domain of a target system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.