Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
ToolKoadic | Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain. |
| T1016 System Network Configuration Discovery |
ToolPupy | Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions. |
| T1016 System Network Configuration Discovery |
ToolQuasarRAT | QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`. |
| T1016 System Network Configuration Discovery |
ToolAdFind | AdFind can extract subnet information from Active Directory. |
| T1016 System Network Configuration Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to enumerate network interfaces. |
| T1016 System Network Configuration Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`. |
| T1016 System Network Configuration Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses. |
| T1016 System Network Configuration Discovery |
GroupShinyHunters | ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
| T1016 System Network Configuration Discovery |
MalwareBADFLICK | BADFLICK has captured victim IP address details. |
| T1016 System Network Configuration Discovery |
MalwareDuqu | The reconnaissance modules used with Duqu can collect information on network configuration. |
| T1016.001 Internet Connection Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
| T1016.001 Internet Connection Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity. |
| T1016.001 Internet Connection Discovery |
GroupVolt Typhoon | Volt Typhoon has employed Ping to check network connectivity. |
| T1016.001 Internet Connection Discovery |
GroupHAFNIUM | HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| T1016.001 Internet Connection Discovery |
GroupGamaredon Group | Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status. |
| T1016.001 Internet Connection Discovery |
GroupTA2541 | TA2541 has run scripts to check internet connectivity from compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupTurla | Turla has used |
| T1016.001 Internet Connection Discovery |
GroupLotus Blossom | Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| T1016.001 Internet Connection Discovery |
GroupAPT29 | APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| T1016.001 Internet Connection Discovery |
GroupHEXANE | HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupMagic Hound | Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| T1016.001 Internet Connection Discovery |
GroupFIN8 | FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| T1016.001 Internet Connection Discovery |
GroupFIN13 | FIN13 has used `Ping` and `tracert` for network reconnaissance efforts. |
| T1016.001 Internet Connection Discovery |
MalwareQuietSieve | QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS). |
| T1016.001 Internet Connection Discovery |
MalwareHavoc | The Havoc demon can check for a connection to the C2 server from the target machine. |
| T1016.001 Internet Connection Discovery |
MalwarePUBLOAD | PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`. |
| T1016.001 Internet Connection Discovery |
MalwareWoody RAT | Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks. |
| T1016.001 Internet Connection Discovery |
MalwareSUGARUSH | SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection. |
| T1016.001 Internet Connection Discovery |
MalwareNeoichor | Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`. |
| T1016.001 Internet Connection Discovery |
MalwareRising Sun | Rising Sun can test a connection to a specified network IP address over a specified port number. |
| T1016.001 Internet Connection Discovery |
MalwareDarkTortilla | DarkTortilla can check for internet connectivity by issuing HTTP GET requests. |
| T1016.001 Internet Connection Discovery |
MalwareGoldFinder | GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through. |
| T1016.001 Internet Connection Discovery |
MalwareNKAbuse | NKAbuse utilizes external services such as |
| T1016.001 Internet Connection Discovery |
MalwareMore_eggs | More_eggs has used HTTP GET requests to check internet connectivity. |
| T1016.001 Internet Connection Discovery |
MalwareSysUpdate | SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process. |
| T1016.001 Internet Connection Discovery |
MalwareQakBot | QakBot can measure the download speed on a targeted host. |
| T1016.002 Wi-Fi Discovery |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system. |
| T1016.002 Wi-Fi Discovery |
GroupMagic Hound | Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1016.002 Wi-Fi Discovery |
MalwareEmotet | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| T1016.002 Wi-Fi Discovery |
MalwareMachete | Machete uses the |
| T1016.002 Wi-Fi Discovery |
MalwarePUBLOAD | PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`. |
| T1016.002 Wi-Fi Discovery |
MalwareCharmPower | CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details. |
| T1016.002 Wi-Fi Discovery |
MalwareAgent Tesla | Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1018 Remote System Discovery |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets. |
| T1018 Remote System Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1018 Remote System Discovery |
CampaignC0015 | During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| T1018 Remote System Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1018 Remote System Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| T1018 Remote System Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance. |
| T1018 Remote System Discovery |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.