Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets. |
| T1018 Remote System Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1018 Remote System Discovery |
CampaignC0015 | During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| T1018 Remote System Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1018 Remote System Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| T1018 Remote System Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance. |
| T1018 Remote System Discovery |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
| T1018 Remote System Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory. |
| T1018 Remote System Discovery |
CampaignLeviathan Australian Intrusions | Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.