ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
ToolKoadic

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1016
System Network Configuration Discovery
ToolPupy

Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions.

T1016
System Network Configuration Discovery
ToolQuasarRAT

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1016
System Network Configuration Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to enumerate network interfaces.

T1016
System Network Configuration Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`.

T1016
System Network Configuration Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1016
System Network Configuration Discovery
GroupShinyHunters

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.

T1016
System Network Configuration Discovery
MalwareBADFLICK

BADFLICK has captured victim IP address details.

T1016
System Network Configuration Discovery
MalwareDuqu

The reconnaissance modules used with Duqu can collect information on network configuration.

T1016.001
Internet Connection Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

T1016.001
Internet Connection Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used a Visual Basic script that checked for internet connectivity.

T1016.001
Internet Connection Discovery
GroupVolt Typhoon

Volt Typhoon has employed Ping to check network connectivity.

T1016.001
Internet Connection Discovery
GroupHAFNIUM

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

T1016.001
Internet Connection Discovery
GroupGamaredon Group

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

T1016.001
Internet Connection Discovery
GroupTA2541

TA2541 has run scripts to check internet connectivity from compromised hosts.

T1016.001
Internet Connection Discovery
GroupTurla

Turla has used tracert to check internet connectivity.

T1016.001
Internet Connection Discovery
GroupLotus Blossom

Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet.

T1016.001
Internet Connection Discovery
GroupAPT29

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

T1016.001
Internet Connection Discovery
GroupHEXANE

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

T1016.001
Internet Connection Discovery
GroupMagic Hound

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

T1016.001
Internet Connection Discovery
GroupFIN8

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

T1016.001
Internet Connection Discovery
GroupFIN13

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

T1016.001
Internet Connection Discovery
MalwareQuietSieve

QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS).

T1016.001
Internet Connection Discovery
MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

T1016.001
Internet Connection Discovery
MalwarePUBLOAD

PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`.

T1016.001
Internet Connection Discovery
MalwareWoody RAT

Woody RAT can make `Ping` GET HTTP requests to its C2 server at regular intervals for network connectivity checks.

T1016.001
Internet Connection Discovery
MalwareSUGARUSH

SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection.

T1016.001
Internet Connection Discovery
MalwareNeoichor

Neoichor can check for Internet connectivity by contacting bing[.]com with the request format `bing[.]com?id=<GetTickCount>`.

T1016.001
Internet Connection Discovery
MalwareRising Sun

Rising Sun can test a connection to a specified network IP address over a specified port number.

T1016.001
Internet Connection Discovery
MalwareDarkTortilla

DarkTortilla can check for internet connectivity by issuing HTTP GET requests.

T1016.001
Internet Connection Discovery
MalwareGoldFinder

GoldFinder performed HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request traveled through.

T1016.001
Internet Connection Discovery
MalwareNKAbuse

NKAbuse utilizes external services such as ifconfig.me to identify the victim machine's IP address.

T1016.001
Internet Connection Discovery
MalwareMore_eggs

More_eggs has used HTTP GET requests to check internet connectivity.

T1016.001
Internet Connection Discovery
MalwareSysUpdate

SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process.

T1016.001
Internet Connection Discovery
MalwareQakBot

QakBot can measure the download speed on a targeted host.

T1016.002
Wi-Fi Discovery
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system.

T1016.002
Wi-Fi Discovery
GroupMagic Hound

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

T1016.002
Wi-Fi Discovery
MalwareEmotet

Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.

T1016.002
Wi-Fi Discovery
MalwareMachete

Machete uses the netsh wlan show networks mode=bssid and netsh wlan show interfaces commands to list all nearby WiFi networks and connected interfaces.

T1016.002
Wi-Fi Discovery
MalwarePUBLOAD

PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`.

T1016.002
Wi-Fi Discovery
MalwareCharmPower

CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details.

T1016.002
Wi-Fi Discovery
MalwareAgent Tesla

Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.

T1018
Remote System Discovery
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.

T1018
Remote System Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1018
Remote System Discovery
CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1018
Remote System Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1018
Remote System Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

T1018
Remote System Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

T1018
Remote System Discovery
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.