ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1018×

9 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.

T1018
Remote System Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1018
Remote System Discovery
CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1018
Remote System Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1018
Remote System Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

T1018
Remote System Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

T1018
Remote System Discovery
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD.

T1018
Remote System Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory.

T1018
Remote System Discovery
CampaignLeviathan Australian Intrusions

Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.