Real-world descriptions of how a group, tool or campaign used a technique.
232 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareLizar | Lizar has retrieved network information from a compromised host, such as the MAC address. |
| T1016 System Network Configuration Discovery |
MalwareDtrack | Dtrack can collect the host's IP addresses using the |
| T1016 System Network Configuration Discovery |
MalwareLoudMiner | LoudMiner used a script to gather the IP address of the infected machine before sending to the C2. |
| T1016 System Network Configuration Discovery |
MalwareAzorult | Azorult can collect host IP information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's proxy information. |
| T1016 System Network Configuration Discovery |
MalwareFALLCHILL | FALLCHILL collects MAC address and local IP address information from the victim. |
| T1016 System Network Configuration Discovery |
MalwareXORIndex Loader | XORIndex Loader has leveraged webservices to identify the public IP of the victim host. |
| T1016 System Network Configuration Discovery |
MalwareSmall Sieve | Small Sieve can obtain the IP address of a victim host. |
| T1016 System Network Configuration Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host. |
| T1016 System Network Configuration Discovery |
ToolSliver | Sliver has the ability to gather network configuration information. |
| T1016 System Network Configuration Discovery |
Toolevilginx2 | evilginx2 can capture information from each session with a victim including the public IP used to access the server and the user agent. |
| T1016 System Network Configuration Discovery |
Toolipconfig | ipconfig can be used to display adapter configuration on Windows systems, including information for TCP/IP, DNS, and DHCP. |
| T1016 System Network Configuration Discovery |
ToolArp | Arp can be used to display ARP configuration information on the host. |
| T1016 System Network Configuration Discovery |
ToolEmpire | Empire can acquire network configuration information like DNS servers, public IP, and network proxies used by a host. |
| T1016 System Network Configuration Discovery |
Toolifconfig | ifconfig can be used to display adapter configuration on Unix systems, including information for TCP/IP, DNS, and DHCP. |
| T1016 System Network Configuration Discovery |
ToolPcShare | PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`. |
| T1016 System Network Configuration Discovery |
ToolPoshC2 | PoshC2 can enumerate network adapter information. |
| T1016 System Network Configuration Discovery |
ToolAsyncRAT | AsyncRAT can enumerate the NetBIOS name on targeted machines. |
| T1016 System Network Configuration Discovery |
ToolNltest | Nltest may be used to enumerate the parent domain of a local machine using |
| T1016 System Network Configuration Discovery |
Toolnbtstat | nbtstat can be used to discover local NetBIOS domain names. |
| T1016 System Network Configuration Discovery |
ToolNBTscan | NBTscan can be used to collect MAC addresses. |
| T1016 System Network Configuration Discovery |
Toolroute | route can be used to discover routing configuration information. |
| T1016 System Network Configuration Discovery |
ToolCrackMapExec | CrackMapExec can collect DNS information from the targeted system. |
| T1016 System Network Configuration Discovery |
ToolKoadic | Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain. |
| T1016 System Network Configuration Discovery |
ToolPupy | Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions. |
| T1016 System Network Configuration Discovery |
ToolQuasarRAT | QuasarRAT has the ability to enumerate the Wide Area Network (WAN) IP through requests to ip-api[.]com, freegeoip[.]net, or api[.]ipify[.]org observed with user-agent string `Mozilla/5.0 (Windows NT 6.3; rv:48.0) Gecko/20100101 Firefox/48.0`. |
| T1016 System Network Configuration Discovery |
ToolAdFind | AdFind can extract subnet information from Active Directory. |
| T1016 System Network Configuration Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to enumerate network interfaces. |
| T1016 System Network Configuration Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`. |
| T1016 System Network Configuration Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for source IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareBADFLICK | BADFLICK has captured victim IP address details. |
| T1016 System Network Configuration Discovery |
MalwareDuqu | The reconnaissance modules used with Duqu can collect information on network configuration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.