ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016
System Network Configuration Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1016
System Network Configuration Discovery
GroupShinyHunters

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.

T1016.001
Internet Connection Discovery
GroupVolt Typhoon

Volt Typhoon has employed Ping to check network connectivity.

T1016.001
Internet Connection Discovery
GroupHAFNIUM

HAFNIUM has checked for network connectivity from a compromised host using `ping`, including attempts to contact `google[.]com`.

T1016.001
Internet Connection Discovery
GroupGamaredon Group

Gamaredon Group has tested connectivity between a compromised machine and a C2 server using Ping with commands such as `CSIDL_SYSTEM\cmd.exe /c ping -n 1`. Gamaredon Group has searched the ping records to obtain the C2 address and has used ping to search for the C2’s status.

T1016.001
Internet Connection Discovery
GroupTA2541

TA2541 has run scripts to check internet connectivity from compromised hosts.

T1016.001
Internet Connection Discovery
GroupTurla

Turla has used tracert to check internet connectivity.

T1016.001
Internet Connection Discovery
GroupLotus Blossom

Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet.

T1016.001
Internet Connection Discovery
GroupAPT29

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

T1016.001
Internet Connection Discovery
GroupHEXANE

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

T1016.001
Internet Connection Discovery
GroupMagic Hound

Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity.

T1016.001
Internet Connection Discovery
GroupFIN8

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

T1016.001
Internet Connection Discovery
GroupFIN13

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

T1016.002
Wi-Fi Discovery
GroupMagic Hound

Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected.

T1018
Remote System Discovery
GroupIndrik Spider

Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.

T1018
Remote System Discovery
GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

T1018
Remote System Discovery
GroupGALLIUM

GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as ping to identify remote systems.

T1018
Remote System Discovery
GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

T1018
Remote System Discovery
GroupVolt Typhoon

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1018
Remote System Discovery
GroupAPT41

APT41 has used MiPing to discover active systems in the victim network.

T1018
Remote System Discovery
GroupDragonfly

Dragonfly has likely obtained a list of hosts in the victim environment.

T1018
Remote System Discovery
GroupmenuPass

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1018
Remote System Discovery
GroupAPT32

APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.

T1018
Remote System Discovery
GroupHAFNIUM

HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`.

T1018
Remote System Discovery
GroupNaikon

Naikon has used a netbios scanner for remote machine identification.

T1018
Remote System Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1018
Remote System Discovery
GroupLeafminer

Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems.

T1018
Remote System Discovery
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.

T1018
Remote System Discovery
GroupMustang Panda

Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1018
Remote System Discovery
GroupRocke

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.

T1018
Remote System Discovery
GroupScattered Spider

Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1018
Remote System Discovery
GroupAkira

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.

T1018
Remote System Discovery
GroupKe3chang

Ke3chang has used network scanning and enumeration tools, including Ping.

T1018
Remote System Discovery
GroupTurla

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1018
Remote System Discovery
GroupFIN5

FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets.

T1018
Remote System Discovery
GroupLotus Blossom

Lotus Blossom has used Ping to identify remote systems.

T1018
Remote System Discovery
GroupChimera

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.

T1018
Remote System Discovery
GroupMirrorFace

MirrorFace has used Ping for system discovery.

T1018
Remote System Discovery
GroupMedusa Group

Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.

T1018
Remote System Discovery
GroupBRONZE BUTLER

BRONZE BUTLER typically use ping and Net to enumerate systems.

T1018
Remote System Discovery
GroupDeep Panda

Deep Panda has used ping to identify other machines of interest.

T1018
Remote System Discovery
GroupEmber Bear

Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.

T1018
Remote System Discovery
GroupToddyCat

ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery.

T1018
Remote System Discovery
GroupAgrius

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

T1018
Remote System Discovery
GroupFox Kitten

Fox Kitten has used Angry IP Scanner to detect remote systems.

T1018
Remote System Discovery
GroupEarth Lusca

Earth Lusca used the command powershell “Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list -
property * | findstr “Address””
to find the network information of successfully logged-in accounts to discovery addresses of other machines. Earth Lusca has also used multiple scanning tools to discover other machines within the same compromised network.

T1018
Remote System Discovery
GroupSilence

Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.