Technique.View on attack.mitre.org
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of discovery techniques depending on the operating system, but the resulting information may include details about the networked cloud environment relevant to the adversary's goals. Cloud providers may have different ways in which their virtual networks operate. Similarly, adversaries who gain access to network devices may also perform similar discovery activities to gather information about connected systems and services.
Utilities and commands that acquire this information include netstat, "net use," and "net session" with Net. In Mac and Linux, netstat and lsof can be used to list current connections. who -a and w can be used to show which users are currently logged in, similar to "net session". Additionally, built-in features native to network devices and Network Device CLI may be used (e.g. show ip sockets, show tcp brief). On ESXi servers, the command `esxi network ip connection list` can be used to list active network connections.
Rules on DetectionCode tagged with T1049.
| Rule | Level | Log source |
|---|---|---|
| HackTool - SharpView Execution | high | windows / process_creation |
| Cisco Discovery | low | cisco / NULL |
| System Network Connections Discovery - Linux | low | linux / process_creation |
| System Network Connections Discovery Via Net.EXE | low | windows / process_creation |
| Use Get-NetTCPConnection | low | windows / ps_classic_start |
| Use Get-NetTCPConnection - PowerShell Module | low | windows / ps_module |
| System Network Connections Discovery - MacOs | informational | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| GetNetTcpconnection with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetNetTcpconnection with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Network Connection Discovery With Arp | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Network Connection Discovery With Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Network Connection Discovery With Netstat | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Common Abused Cmd Shell Risk Behavior | Correlation | NULL | |
| Windows Network Connection Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL | |
| Windows System Network Connections Discovery Netsh | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: |
| GroupAndariel | Andariel has used the |
| GroupAPT1 | APT1 used the |
| GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| GroupAPT32 | APT32 used the |
| GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| GroupAPT5 | APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| Used by | Procedure example |
|---|---|
| MalwareAria-body | Aria-body has the ability to gather TCP and UDP table status listings. |
| MalwareBabuk | Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption. |
| MalwareBADHATCH | BADHATCH can execute `netstat.exe -f` on a compromised machine. |
| MalwareBlackEnergy | BlackEnergy has gathered information about local network connections using netstat. |
| MalwareCarbon | Carbon uses the |
| MalwareCobalt Strike | Cobalt Strike can produce a sessions report from compromised hosts. |
| MalwareComnie | Comnie executes the |
| MalwareConti | Conti can enumerate routine network connections from a compromised host. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`. |
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map internal network architecture and access relationships. |
| CampaignFunnyDream | During FunnyDream, the threat actors used netstat to discover network connections on remote systems. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance. |
| CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.