Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupFIN13 | FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information. |
| T1016 System Network Configuration Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
GroupShinyHunters | ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
| T1016.001 Internet Connection Discovery |
GroupVolt Typhoon | Volt Typhoon has employed Ping to check network connectivity. |
| T1016.001 Internet Connection Discovery |
GroupHAFNIUM | HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`. |
| T1016.001 Internet Connection Discovery |
GroupGamaredon Group | Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status. |
| T1016.001 Internet Connection Discovery |
GroupTA2541 | TA2541 has run scripts to check internet connectivity from compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupTurla | Turla has used |
| T1016.001 Internet Connection Discovery |
GroupLotus Blossom | Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| T1016.001 Internet Connection Discovery |
GroupAPT29 | APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| T1016.001 Internet Connection Discovery |
GroupHEXANE | HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupMagic Hound | Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| T1016.001 Internet Connection Discovery |
GroupFIN8 | FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| T1016.001 Internet Connection Discovery |
GroupFIN13 | FIN13 has used `Ping` and `tracert` for network reconnaissance efforts. |
| T1016.002 Wi-Fi Discovery |
GroupMagic Hound | Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1018 Remote System Discovery |
GroupIndrik Spider | Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database. |
| T1018 Remote System Discovery |
GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1018 Remote System Discovery |
GroupGALLIUM | GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as |
| T1018 Remote System Discovery |
GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| T1018 Remote System Discovery |
GroupVolt Typhoon | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1018 Remote System Discovery |
GroupAPT41 | APT41 has used MiPing to discover active systems in the victim network. |
| T1018 Remote System Discovery |
GroupDragonfly | Dragonfly has likely obtained a list of hosts in the victim environment. |
| T1018 Remote System Discovery |
GroupmenuPass | menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1018 Remote System Discovery |
GroupAPT32 | APT32 has enumerated DC servers using the command |
| T1018 Remote System Discovery |
GroupHAFNIUM | HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`. |
| T1018 Remote System Discovery |
GroupNaikon | Naikon has used a netbios scanner for remote machine identification. |
| T1018 Remote System Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1018 Remote System Discovery |
GroupLeafminer | Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems. |
| T1018 Remote System Discovery |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1018 Remote System Discovery |
GroupMustang Panda | Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1018 Remote System Discovery |
GroupRocke | Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them. |
| T1018 Remote System Discovery |
GroupScattered Spider | Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1018 Remote System Discovery |
GroupAkira | Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks. |
| T1018 Remote System Discovery |
GroupKe3chang | Ke3chang has used network scanning and enumeration tools, including Ping. |
| T1018 Remote System Discovery |
GroupTurla | Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1018 Remote System Discovery |
GroupFIN5 | FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets. |
| T1018 Remote System Discovery |
GroupLotus Blossom | Lotus Blossom has used Ping to identify remote systems. |
| T1018 Remote System Discovery |
GroupChimera | Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment. |
| T1018 Remote System Discovery |
GroupMirrorFace | MirrorFace has used Ping for system discovery. |
| T1018 Remote System Discovery |
GroupMedusa Group | Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network. |
| T1018 Remote System Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER typically use |
| T1018 Remote System Discovery |
GroupDeep Panda | Deep Panda has used ping to identify other machines of interest. |
| T1018 Remote System Discovery |
GroupEmber Bear | Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery. |
| T1018 Remote System Discovery |
GroupToddyCat | ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery. |
| T1018 Remote System Discovery |
GroupAgrius | Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| T1018 Remote System Discovery |
GroupFox Kitten | Fox Kitten has used Angry IP Scanner to detect remote systems. |
| T1018 Remote System Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1018 Remote System Discovery |
GroupSilence | Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.