ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1049×

32 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
GroupAPT38

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

T1049
System Network Connections Discovery
GroupGALLIUM

GALLIUM used netstat -oan to obtain information about the victim network connections.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1049
System Network Connections Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: netstat -ano >> %temp%\download

T1049
System Network Connections Discovery
GroupVolt Typhoon

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.

T1049
System Network Connections Discovery
GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

T1049
System Network Connections Discovery
GroupmenuPass

menuPass has used net use to conduct connectivity checks to machines.

T1049
System Network Connections Discovery
GroupAPT32

APT32 used the netstat -anpo tcp command to display TCP connections on the victim's machine.

T1049
System Network Connections Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.

T1049
System Network Connections Discovery
GroupTeamTNT

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1049
System Network Connections Discovery
GroupSandworm Team

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.

T1049
System Network Connections Discovery
GroupAndariel

Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.

T1049
System Network Connections Discovery
GroupMustang Panda

Mustang Panda has used netstat -ano to determine network connection information.

T1049
System Network Connections Discovery
GroupOilRig

OilRig has used netstat -an on a victim to get a listing of network connections.

T1049
System Network Connections Discovery
GroupTropic Trooper

Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts.

T1049
System Network Connections Discovery
GroupKe3chang

Ke3chang performs local network connection discovery using netstat.

T1049
System Network Connections Discovery
GroupAPT1

APT1 used the net use command to get a listing on network connections.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1049
System Network Connections Discovery
GroupPoseidon Group

Poseidon Group obtains and saves information about victim network interfaces and addresses.

T1049
System Network Connections Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `netstat` to identify system network connections.

T1049
System Network Connections Discovery
GroupChimera

Chimera has used netstat -ano | findstr EST to discover network connections.

T1049
System Network Connections Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports.

T1049
System Network Connections Discovery
GroupToddyCat

ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts.

T1049
System Network Connections Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

T1049
System Network Connections Discovery
GroupLazarus Group

Lazarus Group has used net use to identify and establish a network connection with a remote host.

T1049
System Network Connections Discovery
GroupINC Ransom

INC Ransom has used RDP to test network connections.

T1049
System Network Connections Discovery
GroupEarth Lusca

Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational”
(Event ID 1024) to obtain network information from RDP connections. Earth Lusca has also used netstat from a compromised system to obtain network connection information.

T1049
System Network Connections Discovery
GroupVelvet Ant

Velvet Ant has enumerated existing network connections on victim devices.

T1049
System Network Connections Discovery
GroupHEXANE

HEXANE has used netstat to monitor connections to specific ports.

T1049
System Network Connections Discovery
GroupMagic Hound

Magic Hound has used quser.exe to identify existing RDP connections.

T1049
System Network Connections Discovery
GroupThreat Group-3390

Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim.

T1049
System Network Connections Discovery
GroupFIN13

FIN13 has used `netstat` and other net commands for network reconnaissance efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.