ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016×

232 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLizar

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1016
System Network Configuration Discovery
MalwareDtrack

Dtrack can collect the host's IP addresses using the ipconfig command.

T1016
System Network Configuration Discovery
MalwareLoudMiner

LoudMiner used a script to gather the IP address of the infected machine before sending to the C2.

T1016
System Network Configuration Discovery
MalwareAzorult

Azorult can collect host IP information from the victim’s machine.

T1016
System Network Configuration Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's proxy information.

T1016
System Network Configuration Discovery
MalwareFALLCHILL

FALLCHILL collects MAC address and local IP address information from the victim.

T1016
System Network Configuration Discovery
MalwareXORIndex Loader

XORIndex Loader has leveraged webservices to identify the public IP of the victim host.

T1016
System Network Configuration Discovery
MalwareSmall Sieve

Small Sieve can obtain the IP address of a victim host.

T1016
System Network Configuration Discovery
ToolShimRatReporter

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1016
System Network Configuration Discovery
ToolSliver

Sliver has the ability to gather network configuration information.

T1016
System Network Configuration Discovery
Toolevilginx2

evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent.

T1016
System Network Configuration Discovery
Toolipconfig

ipconfig can be used to display adapter configuration on Windows systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolArp

Arp can be used to display ARP configuration information on the host.

T1016
System Network Configuration Discovery
ToolEmpire

Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host.

T1016
System Network Configuration Discovery
Toolifconfig

ifconfig can be used to display adapter configuration on Unix systems, including information for TCP/IP, DNS, and DHCP.

T1016
System Network Configuration Discovery
ToolPcShare

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1016
System Network Configuration Discovery
ToolPoshC2

PoshC2 can enumerate network adapter information.

T1016
System Network Configuration Discovery
ToolAsyncRAT

AsyncRAT can enumerate the NetBIOS name on targeted machines.

T1016
System Network Configuration Discovery
ToolNltest

Nltest may be used to enumerate the parent domain of a local machine using /parentdomain.

T1016
System Network Configuration Discovery
Toolnbtstat

nbtstat can be used to discover local NetBIOS domain names.

T1016
System Network Configuration Discovery
ToolNBTscan

NBTscan can be used to collect MAC addresses.

T1016
System Network Configuration Discovery
Toolroute

route can be used to discover routing configuration information.

T1016
System Network Configuration Discovery
ToolCrackMapExec

CrackMapExec can collect DNS information from the targeted system.

T1016
System Network Configuration Discovery
ToolKoadic

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1016
System Network Configuration Discovery
ToolPupy

Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions.

T1016
System Network Configuration Discovery
ToolQuasarRAT

QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`.

T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1016
System Network Configuration Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to enumerate network interfaces.

T1016
System Network Configuration Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`.

T1016
System Network Configuration Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses.

T1016
System Network Configuration Discovery
MalwareBADFLICK

BADFLICK has captured victim IP address details.

T1016
System Network Configuration Discovery
MalwareDuqu

The reconnaissance modules used with Duqu can collect information on network configuration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.