Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
CampaignCostaRicto | During CostaRicto, the threat actors employed nmap and pscan to scan target environments. |
| T1046 Network Service Discovery |
GroupBlackByte | BlackByte has used tools such as NetScan to enumerate network services in victim environments. |
| T1046 Network Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery. |
| T1046 Network Service Discovery |
GroupAPT41 | APT41 used a malware variant called WIDETONE to conduct port scans on specified subnets. |
| T1046 Network Service Discovery |
GroupmenuPass | menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest. |
| T1046 Network Service Discovery |
GroupAPT32 | APT32 performed network scanning on the network to search for open ports, services, OS finger-printing, and other vulnerabilities. |
| T1046 Network Service Discovery |
GroupNaikon | Naikon has used the LadonGo scanner to scan target networks. |
| T1046 Network Service Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1046 Network Service Discovery |
GroupLeafminer | Leafminer scanned network services to search for vulnerabilities in the victim system. |
| T1046 Network Service Discovery |
GroupTeamTNT | TeamTNT has used masscan to search for open Docker API ports and Kubernetes clusters. TeamTNT has also used malware that utilizes zmap and zgrab to search for vulnerable services in cloud environments. |
| T1046 Network Service Discovery |
GroupMustang Panda | Mustang Panda has leveraged NBTscan to scan IP networks. |
| T1046 Network Service Discovery |
GroupRocke | Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers. |
| T1046 Network Service Discovery |
GroupAPT39 | APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| T1046 Network Service Discovery |
GroupOilRig | OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning. |
| T1046 Network Service Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1046 Network Service Discovery |
GroupSuckfly | Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open. |
| T1046 Network Service Discovery |
GroupBlackTech | BlackTech has used the SNScan tool to find other potential targets on victim networks. |
| T1046 Network Service Discovery |
GroupDarkVishnya | DarkVishnya performed port scanning to obtain the list of active services. |
| T1046 Network Service Discovery |
GroupRedCurl | RedCurl has used netstat to check if port 4119 is open. |
| T1046 Network Service Discovery |
GroupLotus Blossom | Lotus Blossom has used port scanners to enumerate services on remote hosts. |
| T1046 Network Service Discovery |
GroupChimera | Chimera has used the |
| T1046 Network Service Discovery |
GroupMedusa Group | Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration. Medusa Group has also utilized the publicly available scanning tool SoftPerfect Network Scanner (`netscan.exe`) to discover device hostnames and network services. |
| T1046 Network Service Discovery |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware. |
| T1046 Network Service Discovery |
GroupEmber Bear | Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments. |
| T1046 Network Service Discovery |
GroupAgrius | Agrius used the open-source port scanner |
| T1046 Network Service Discovery |
GroupFox Kitten | Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports. |
| T1046 Network Service Discovery |
GroupLazarus Group | Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network. |
| T1046 Network Service Discovery |
GroupINC Ransom | INC Ransom has used NETSCAN.EXE for internal reconnaissance. |
| T1046 Network Service Discovery |
GroupCobalt Group | Cobalt Group leveraged an open-source tool called SoftPerfect Network Scanner to perform network scanning. |
| T1046 Network Service Discovery |
GroupMagic Hound | Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning. |
| T1046 Network Service Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems. |
| T1046 Network Service Discovery |
GroupFIN13 | FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network. |
| T1046 Network Service Discovery |
MalwareHDoor | HDoor scans to identify open ports on the victim. |
| T1046 Network Service Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to scan for open ports on hosts in a connected network. |
| T1046 Network Service Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1046 Network Service Discovery |
MalwareBADHATCH | BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| T1046 Network Service Discovery |
MalwareHildegard | Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1046 Network Service Discovery |
MalwareInvisiMole | InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1046 Network Service Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can scan networks for open ports and listening services. |
| T1046 Network Service Discovery |
MalwareLucifer | Lucifer can scan for open ports including TCP ports 135 and 1433. |
| T1046 Network Service Discovery |
MalwareBlackEnergy | BlackEnergy has conducted port scans on a host. |
| T1046 Network Service Discovery |
MalwareConficker | Conficker scans for other machines to infect. |
| T1046 Network Service Discovery |
MalwareChina Chopper | China Chopper's server component can spider authentication portals. |
| T1046 Network Service Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist file`.It also utilizes Apple's CWWiFiClient API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1046 Network Service Discovery |
MalwareRemsec | Remsec has a plugin that can perform ARP scanning as well as port scanning. |
| T1046 Network Service Discovery |
MalwareXbash | Xbash can perform port scanning of TCP and UDP ports. |
| T1046 Network Service Discovery |
MalwareXTunnel | XTunnel is capable of probing the network for open ports. |
| T1046 Network Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a port scanner on a system. |
| T1046 Network Service Discovery |
MalwareRoyal | Royal can scan the network interfaces of targeted systems. |
| T1046 Network Service Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.