ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLokibot

Lokibot has the ability to discover the domain name of the infected host.

T1016
System Network Configuration Discovery
MalwareFELIXROOT

FELIXROOT collects information about the network including the IP address and DHCP server.

T1016
System Network Configuration Discovery
MalwarePenquin

Penquin can report the IP of the compromised host to attacker controlled infrastructure.

T1016
System Network Configuration Discovery
MalwareBabyShark

BabyShark has executed the ipconfig /all command.

T1016
System Network Configuration Discovery
MalwareCreepySnail

CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings.

T1016
System Network Configuration Discovery
MalwareTroll Stealer

Troll Stealer collects the MAC address of victim devices.

T1016
System Network Configuration Discovery
MalwareManjusaka

Manjusaka gathers information about current network connections, local and remote addresses associated with them, and associated processes.

T1016
System Network Configuration Discovery
MalwareIceApple

The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks.

T1016
System Network Configuration Discovery
MalwareJPIN

JPIN can obtain network information, including DNS, IP, and proxies.

T1016
System Network Configuration Discovery
MalwareSideTwist

SideTwist has the ability to collect the domain name on a compromised host.

T1016
System Network Configuration Discovery
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c ipconfig /all.

T1016
System Network Configuration Discovery
MalwareLunarWeb

LunarWeb can use shell commands to discover network adapters and configuration.

T1016
System Network Configuration Discovery
MalwareOctopus

Octopus can collect the host IP address from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareQilin

Qilin can accept a command line argument identifying specific IPs.

T1016
System Network Configuration Discovery
MalwareSoreFang

SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via ipconfig.exe /all.

T1016
System Network Configuration Discovery
MalwareSTARWHALE

STARWHALE has the ability to collect the IP address of an infected host.

T1016
System Network Configuration Discovery
MalwareIndustroyer

Industroyer’s 61850 payload component enumerates connected network adapters and their corresponding IP addresses.

T1016
System Network Configuration Discovery
MalwareKevin

Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`.

T1016
System Network Configuration Discovery
MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1016
System Network Configuration Discovery
MalwareShadowPad

ShadowPad has collected the domain name of the victim system.

T1016
System Network Configuration Discovery
MalwareAstaroth

Astaroth collects the external IP address from the system.

T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1016
System Network Configuration Discovery
MalwarejRAT

jRAT can gather victim internal and external IPs.

T1016
System Network Configuration Discovery
MalwareDenis

Denis uses ipconfig to gather the IP address from the system.

T1016
System Network Configuration Discovery
MalwareComnie

Comnie uses ipconfig /all and route PRINT to identify network adapter and interface information.

T1016
System Network Configuration Discovery
MalwareOSInfo

OSInfo discovers the current domain information.

T1016
System Network Configuration Discovery
MalwareLizar

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1016
System Network Configuration Discovery
MalwareDtrack

Dtrack can collect the host's IP addresses using the ipconfig command.

T1016
System Network Configuration Discovery
MalwareLoudMiner

LoudMiner used a script to gather the IP address of the infected machine before sending to the C2.

T1016
System Network Configuration Discovery
MalwareAzorult

Azorult can collect host IP information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's proxy information.

T1016
System Network Configuration Discovery
MalwareFALLCHILL

FALLCHILL collects MAC address and local IP address information from the victim.

T1016
System Network Configuration Discovery
MalwareXORIndex Loader

XORIndex Loader has leveraged webservices to identify the public IP of the victim host.

T1016
System Network Configuration Discovery
MalwareSmall Sieve

Small Sieve can obtain the IP address of a victim host.

T1016
System Network Configuration Discovery
ToolShimRatReporter

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1016
System Network Configuration Discovery
ToolSliver

Sliver has the ability to gather network configuration information.

T1016
System Network Configuration Discovery
Toolevilginx2

evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent.

T1016
System Network Configuration Discovery
Toolipconfig

ipconfig can be used to display adapter configuration on Windows systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolArp

Arp can be used to display ARP configuration information on the host.

T1016
System Network Configuration Discovery
ToolEmpire

Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host.

T1016
System Network Configuration Discovery
Toolifconfig

ifconfig can be used to display adapter configuration on Unix systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolPcShare

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1016
System Network Configuration Discovery
ToolPoshC2

PoshC2 can enumerate network adapter information.

T1016
System Network Configuration Discovery
ToolAsyncRAT

AsyncRAT can enumerate the NetBIOS name on targeted machines.

T1016
System Network Configuration Discovery
ToolNltest

Nltest may be used to enumerate the parent domain of a local machine using /parentdomain.

T1016
System Network Configuration Discovery
Toolnbtstat

nbtstat can be used to discover local NetBIOS domain names.

T1016
System Network Configuration Discovery
ToolNBTscan

NBTscan can be used to collect MAC addresses.

T1016
System Network Configuration Discovery
Toolroute

route can be used to discover routing configuration information.

T1016
System Network Configuration Discovery
ToolCrackMapExec

CrackMapExec can collect DNS information from the targeted system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.