Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareLokibot | Lokibot has the ability to discover the domain name of the infected host. |
| T1016 System Network Configuration Discovery |
MalwareFELIXROOT | FELIXROOT collects information about the network including the IP address and DHCP server. |
| T1016 System Network Configuration Discovery |
MalwarePenquin | Penquin can report the IP of the compromised host to attacker controlled infrastructure. |
| T1016 System Network Configuration Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1016 System Network Configuration Discovery |
MalwareCreepySnail | CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings. |
| T1016 System Network Configuration Discovery |
MalwareTroll Stealer | Troll Stealer collects the MAC address of victim devices. |
| T1016 System Network Configuration Discovery |
MalwareManjusaka | Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes. |
| T1016 System Network Configuration Discovery |
MalwareIceApple | The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks. |
| T1016 System Network Configuration Discovery |
MalwareJPIN | JPIN can obtain network information, including DNS, IP, and proxies. |
| T1016 System Network Configuration Discovery |
MalwareSideTwist | SideTwist has the ability to collect the domain name on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1016 System Network Configuration Discovery |
MalwareLunarWeb | LunarWeb can use shell commands to discover network adapters and configuration. |
| T1016 System Network Configuration Discovery |
MalwareOctopus | Octopus can collect the host IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareQilin | Qilin can accept a command line argument identifying specific IPs. |
| T1016 System Network Configuration Discovery |
MalwareSoreFang | SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via |
| T1016 System Network Configuration Discovery |
MalwareSTARWHALE | STARWHALE has the ability to collect the IP address of an infected host. |
| T1016 System Network Configuration Discovery |
MalwareIndustroyer | Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareKevin | Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`. |
| T1016 System Network Configuration Discovery |
MalwareAgent Tesla | Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings. |
| T1016 System Network Configuration Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwareShadowPad | ShadowPad has collected the domain name of the victim system. |
| T1016 System Network Configuration Discovery |
MalwareAstaroth | Astaroth collects the external IP address from the system. |
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1016 System Network Configuration Discovery |
MalwarejRAT | jRAT can gather victim internal and external IPs. |
| T1016 System Network Configuration Discovery |
MalwareDenis | Denis uses |
| T1016 System Network Configuration Discovery |
MalwareComnie | Comnie uses |
| T1016 System Network Configuration Discovery |
MalwareOSInfo | OSInfo discovers the current domain information. |
| T1016 System Network Configuration Discovery |
MalwareLizar | Lizar has retrieved network information from a compromised host, such as the MAC address. |
| T1016 System Network Configuration Discovery |
MalwareDtrack | Dtrack can collect the host's IP addresses using the |
| T1016 System Network Configuration Discovery |
MalwareLoudMiner | LoudMiner used a script to gather the IP address of the infected machine before sending to the C2. |
| T1016 System Network Configuration Discovery |
MalwareAzorult | Azorult can collect host IP information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's proxy information. |
| T1016 System Network Configuration Discovery |
MalwareFALLCHILL | FALLCHILL collects MAC address and local IP address information from the victim. |
| T1016 System Network Configuration Discovery |
MalwareXORIndex Loader | XORIndex Loader has leveraged webservices to identify the public IP of the victim host. |
| T1016 System Network Configuration Discovery |
MalwareSmall Sieve | Small Sieve can obtain the IP address of a victim host. |
| T1016 System Network Configuration Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host. |
| T1016 System Network Configuration Discovery |
ToolSliver | Sliver has the ability to gather network configuration information. |
| T1016 System Network Configuration Discovery |
Toolevilginx2 | evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent. |
| T1016 System Network Configuration Discovery |
Toolipconfig | ipconfig can be used to display adapter configuration on Windows systems, including information for TCP/IP, DNS, and DHCP. |
| T1016 System Network Configuration Discovery |
ToolArp | Arp can be used to display ARP configuration information on the host. |
| T1016 System Network Configuration Discovery |
ToolEmpire | Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host. |
| T1016 System Network Configuration Discovery |
Toolifconfig | ifconfig can be used to display adapter configuration on Unix systems, including information for TCP/IP, DNS, and DHCP. |
| T1016 System Network Configuration Discovery |
ToolPcShare | PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`. |
| T1016 System Network Configuration Discovery |
ToolPoshC2 | PoshC2 can enumerate network adapter information. |
| T1016 System Network Configuration Discovery |
ToolAsyncRAT | AsyncRAT can enumerate the NetBIOS name on targeted machines. |
| T1016 System Network Configuration Discovery |
ToolNltest | Nltest may be used to enumerate the parent domain of a local machine using |
| T1016 System Network Configuration Discovery |
Toolnbtstat | nbtstat can be used to discover local NetBIOS domain names. |
| T1016 System Network Configuration Discovery |
ToolNBTscan | NBTscan can be used to collect MAC addresses. |
| T1016 System Network Configuration Discovery |
Toolroute | route can be used to discover routing configuration information. |
| T1016 System Network Configuration Discovery |
ToolCrackMapExec | CrackMapExec can collect DNS information from the targeted system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.