Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupLazarus Group | Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key: |
| T1012 Query Registry |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| T1012 Query Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool can read and decrypt stored Registry values. |
| T1014 Rootkit |
GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| T1014 Rootkit |
GroupTeamTNT | TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| T1014 Rootkit |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1014 Rootkit |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| T1014 Rootkit |
GroupAPT28 | APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax. |
| T1014 Rootkit |
GroupWinnti Group | Winnti Group used a rootkit to modify typical server functionality. |
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1016 System Network Configuration Discovery |
GroupSideCopy | SideCopy has identified the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
GroupGALLIUM | GALLIUM used |
| T1016 System Network Configuration Discovery |
GroupAPT3 | A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1016 System Network Configuration Discovery |
GroupKimsuky | Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`. |
| T1016 System Network Configuration Discovery |
Groupadmin@338 | admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: |
| T1016 System Network Configuration Discovery |
GroupVolt Typhoon | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1016 System Network Configuration Discovery |
GroupDragonfly | Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain. |
| T1016 System Network Configuration Discovery |
GroupmenuPass | menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1016 System Network Configuration Discovery |
GroupAPT32 | APT32 used the |
| T1016 System Network Configuration Discovery |
GroupHAFNIUM | HAFNIUM has collected IP information via IPInfo. |
| T1016 System Network Configuration Discovery |
GroupMuddyWater | MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1016 System Network Configuration Discovery |
GroupNaikon | Naikon uses commands such as |
| T1016 System Network Configuration Discovery |
GroupTeamTNT | TeamTNT has enumerated the host machine’s IP address. |
| T1016 System Network Configuration Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on network interfaces, including the MAC address. |
| T1016 System Network Configuration Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1016 System Network Configuration Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1016 System Network Configuration Discovery |
GroupScattered Spider | Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1016 System Network Configuration Discovery |
GroupMoses Staff | Moses Staff has collected the domain name of a compromised network. |
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1016 System Network Configuration Discovery |
GroupTropic Trooper | Tropic Trooper has used scripts to collect the host's network topology. |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1016 System Network Configuration Discovery |
GroupAPT1 | APT1 used the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1016 System Network Configuration Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim. |
| T1016 System Network Configuration Discovery |
GroupChimera | Chimera has used ipconfig, Ping, and |
| T1016 System Network Configuration Discovery |
GroupMirrorFace | MirrorFace has used ipconfig for reconnaissance. |
| T1016 System Network Configuration Discovery |
GroupMedusa Group | Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`. |
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1016 System Network Configuration Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1016 System Network Configuration Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1016 System Network Configuration Discovery |
GroupWizard Spider | Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory. |
| T1016 System Network Configuration Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim network configuration. |
| T1016 System Network Configuration Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to enumerate network information. |
| T1016 System Network Configuration Discovery |
GroupHEXANE | |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016 System Network Configuration Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.