Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupIndrik Spider | Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database. |
| T1018 Remote System Discovery |
GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| T1018 Remote System Discovery |
GroupGALLIUM | GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as |
| T1018 Remote System Discovery |
GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| T1018 Remote System Discovery |
GroupVolt Typhoon | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1018 Remote System Discovery |
GroupAPT41 | APT41 has used MiPing to discover active systems in the victim network. |
| T1018 Remote System Discovery |
GroupDragonfly | Dragonfly has likely obtained a list of hosts in the victim environment. |
| T1018 Remote System Discovery |
GroupmenuPass | menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1018 Remote System Discovery |
GroupAPT32 | APT32 has enumerated DC servers using the command |
| T1018 Remote System Discovery |
GroupHAFNIUM | HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`. |
| T1018 Remote System Discovery |
GroupNaikon | Naikon has used a netbios scanner for remote machine identification. |
| T1018 Remote System Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1018 Remote System Discovery |
GroupLeafminer | Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems. |
| T1018 Remote System Discovery |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1018 Remote System Discovery |
GroupMustang Panda | Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1018 Remote System Discovery |
GroupRocke | Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them. |
| T1018 Remote System Discovery |
GroupScattered Spider | Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1018 Remote System Discovery |
GroupAkira | Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks. |
| T1018 Remote System Discovery |
GroupKe3chang | Ke3chang has used network scanning and enumeration tools, including Ping. |
| T1018 Remote System Discovery |
GroupTurla | Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1018 Remote System Discovery |
GroupFIN5 | FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets. |
| T1018 Remote System Discovery |
GroupLotus Blossom | Lotus Blossom has used Ping to identify remote systems. |
| T1018 Remote System Discovery |
GroupChimera | Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment. |
| T1018 Remote System Discovery |
GroupMirrorFace | MirrorFace has used Ping for system discovery. |
| T1018 Remote System Discovery |
GroupMedusa Group | Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network. |
| T1018 Remote System Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER typically use |
| T1018 Remote System Discovery |
GroupDeep Panda | Deep Panda has used ping to identify other machines of interest. |
| T1018 Remote System Discovery |
GroupEmber Bear | Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery. |
| T1018 Remote System Discovery |
GroupToddyCat | ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery. |
| T1018 Remote System Discovery |
GroupAgrius | Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| T1018 Remote System Discovery |
GroupFox Kitten | Fox Kitten has used Angry IP Scanner to detect remote systems. |
| T1018 Remote System Discovery |
GroupEarth Lusca | Earth Lusca used the command |
| T1018 Remote System Discovery |
GroupSilence | Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1018 Remote System Discovery |
GroupPlay | Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks. |
| T1018 Remote System Discovery |
GroupHEXANE | HEXANE has used `net view` to enumerate domain machines. |
| T1018 Remote System Discovery |
GroupMagic Hound | Magic Hound has used Ping for discovery on targeted networks. |
| T1018 Remote System Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used the |
| T1018 Remote System Discovery |
GroupFIN8 | FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used |
| T1018 Remote System Discovery |
GroupShinyHunters | ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.