Real-world descriptions of how a group, tool or campaign used a technique.
44 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupBlackByte | BlackByte used tools such as Arp to pull system network information and identify connected devices. |
| T1016 System Network Configuration Discovery |
GroupSideCopy | SideCopy has identified the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
GroupGALLIUM | GALLIUM used |
| T1016 System Network Configuration Discovery |
GroupAPT3 | A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1016 System Network Configuration Discovery |
GroupKimsuky | Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`. |
| T1016 System Network Configuration Discovery |
Groupadmin@338 | admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: |
| T1016 System Network Configuration Discovery |
GroupVolt Typhoon | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1016 System Network Configuration Discovery |
GroupAPT41 | APT41 collected MAC addresses from victim machines. |
| T1016 System Network Configuration Discovery |
GroupDragonfly | Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain. |
| T1016 System Network Configuration Discovery |
GroupmenuPass | menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1016 System Network Configuration Discovery |
GroupAPT32 | APT32 used the |
| T1016 System Network Configuration Discovery |
GroupHAFNIUM | HAFNIUM has collected IP information via IPInfo. |
| T1016 System Network Configuration Discovery |
GroupMuddyWater | MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1016 System Network Configuration Discovery |
GroupNaikon | Naikon uses commands such as |
| T1016 System Network Configuration Discovery |
GroupTeamTNT | TeamTNT has enumerated the host machine’s IP address. |
| T1016 System Network Configuration Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on network interfaces, including the MAC address. |
| T1016 System Network Configuration Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1016 System Network Configuration Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1016 System Network Configuration Discovery |
GroupScattered Spider | Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`. |
| T1016 System Network Configuration Discovery |
GroupMoses Staff | Moses Staff has collected the domain name of a compromised network. |
| T1016 System Network Configuration Discovery |
GroupOilRig | OilRig has run |
| T1016 System Network Configuration Discovery |
GroupHigaisa | Higaisa used |
| T1016 System Network Configuration Discovery |
GroupTropic Trooper | Tropic Trooper has used scripts to collect the host's network topology. |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1016 System Network Configuration Discovery |
GroupAPT1 | APT1 used the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1016 System Network Configuration Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim. |
| T1016 System Network Configuration Discovery |
GroupChimera | Chimera has used ipconfig, Ping, and |
| T1016 System Network Configuration Discovery |
GroupMirrorFace | MirrorFace has used ipconfig for reconnaissance. |
| T1016 System Network Configuration Discovery |
GroupMedusa Group | Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`. |
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1016 System Network Configuration Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1016 System Network Configuration Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1016 System Network Configuration Discovery |
GroupWizard Spider | Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory. |
| T1016 System Network Configuration Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim network configuration. |
| T1016 System Network Configuration Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to enumerate network information. |
| T1016 System Network Configuration Discovery |
GroupHEXANE | |
| T1016 System Network Configuration Discovery |
GroupMagic Hound | Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016 System Network Configuration Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
| T1016 System Network Configuration Discovery |
GroupFIN13 | FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information. |
| T1016 System Network Configuration Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1016 System Network Configuration Discovery |
GroupShinyHunters | ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.