Technique.View on attack.mitre.org
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, `esxcli network diag ping`.
Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.
Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).
Rules on DetectionCode tagged with T1018.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco IOS XE Remote Access Probe Burst | Anomaly | NULL | Cisco IOS Logs |
| Cisco Secure Firewall - Blocked Connection | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Repeated Blocked Connections | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Domain Controller Discovery with Nltest | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Controller Discovery with Wmic | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetAdComputer with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetAdComputer with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| GetDomainComputer with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetDomainComputer with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| GetDomainController with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetDomainController with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| GetWmiObject Ds Computer with PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetWmiObject Ds Computer with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote System Discovery with Adsisearcher | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote System Discovery with Dsquery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote System Discovery with Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote System Discovery with Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows AdFind Exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Get-AdComputer Unconstrained Delegation Discovery | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Netspy Network Scanner Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows PowerView Constrained Delegation Discovery | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PowerView Unconstrained Delegation Discovery | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows PsTools Recon Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| GroupAkira | Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks. |
| GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| GroupAPT32 | APT32 has enumerated DC servers using the command |
| GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| GroupAPT41 | APT41 has used MiPing to discover active systems in the victim network. |
| GroupBlackByte | BlackByte used tools such as Arp to identify remotely-connected devices. |
| GroupBRONZE BUTLER | BRONZE BUTLER typically use |
| Used by | Procedure example |
|---|---|
| ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| ToolArp | Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems. |
| MalwareBackdoor.Oldrea | Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| MalwareBADHATCH | BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer. |
| MalwareBazar | Bazar can enumerate remote systems using |
| MalwareBitPaymer | BitPaymer can use |
| MalwareBlack Basta | Black Basta can use LDAP queries to connect to AD and iterate over connected workstations. |
| MalwareBlackCat | BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets. |
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD. |
| CampaignC0015 | During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| CampaignFunnyDream | During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks. |
| CampaignLeviathan Australian Intrusions | Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.