Network Topology

T1590.004

Sub-technique of T1590 Gather Victim Network Information.View on attack.mitre.org

About this technique

Adversaries may gather information about the victim's network topology that can be used during targeting. Information about network topologies may include a variety of details, including the physical and/or logical arrangement of both external-facing and internal network environments. This information may also include specifics regarding network devices (gateways, routers, etc.) and other infrastructure.

Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Information about network topologies may also be exposed to adversaries via online or other accessible data sets (ex: Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).

Detection rules0

Rules on DetectionCode tagged with T1590.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software0

None recorded.

Campaigns1

Procedure examples5

Groups4

Used byProcedure example
GroupFIN13

FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts.

GroupMuddyWater

MuddyWater has mapped target networks; access to this information and more is then shared/sold to other Iran threat actors.

GroupSalt Typhoon

Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments.

GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.

Campaigns1

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map a complete network topology of the target infrastructure.

References1

  1. DNS Dumpster Open source
    Hacker Target. (n.d.). DNS Dumpster. Retrieved October 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.