ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1016×

44 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

T1016
System Network Configuration Discovery
GroupSideCopy

SideCopy has identified the IP address of a compromised host.

T1016
System Network Configuration Discovery
GroupGALLIUM

GALLIUM used ipconfig /all to obtain information about the victim network configuration. The group also ran a modified version of NBTscan to identify available NetBIOS name servers.

T1016
System Network Configuration Discovery
GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1016
System Network Configuration Discovery
GroupKimsuky

Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`.

T1016
System Network Configuration Discovery
Groupadmin@338

admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: ipconfig /all >> %temp%\download

T1016
System Network Configuration Discovery
GroupVolt Typhoon

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.

T1016
System Network Configuration Discovery
GroupAPT41

APT41 collected MAC addresses from victim machines.

T1016
System Network Configuration Discovery
GroupDragonfly

Dragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.

T1016
System Network Configuration Discovery
GroupmenuPass

menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions.

T1016
System Network Configuration Discovery
GroupAPT32

APT32 used the ipconfig /all command to gather the IP address from the system.

T1016
System Network Configuration Discovery
GroupHAFNIUM

HAFNIUM has collected IP information via IPInfo.

T1016
System Network Configuration Discovery
GroupMuddyWater

MuddyWater has used malware to collect the victim’s IP address and domain name.

T1016
System Network Configuration Discovery
GroupNaikon

Naikon uses commands such as netsh interface show to discover network interface settings.

T1016
System Network Configuration Discovery
GroupTeamTNT

TeamTNT has enumerated the host machine’s IP address.

T1016
System Network Configuration Discovery
GroupSidewinder

Sidewinder has used malware to collect information on network interfaces, including the MAC address.

T1016
System Network Configuration Discovery
GroupMustang Panda

Mustang Panda has used ipconfig and arp to determine network configuration information. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1016
System Network Configuration Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to enumerate proxy settings in the target environment.

T1016
System Network Configuration Discovery
GroupScattered Spider

Scattered Spider has used network reconnaissance commands for discovery including `ping` and `nltest`.

T1016
System Network Configuration Discovery
GroupMoses Staff

Moses Staff has collected the domain name of a compromised network.

T1016
System Network Configuration Discovery
GroupOilRig

OilRig has run ipconfig /all on a victim.

T1016
System Network Configuration Discovery
GroupHigaisa

Higaisa used ipconfig to gather network configuration information.

T1016
System Network Configuration Discovery
GroupTropic Trooper

Tropic Trooper has used scripts to collect the host's network topology.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1016
System Network Configuration Discovery
GroupAPT1

APT1 used the ipconfig /all command to gather network configuration information.

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1016
System Network Configuration Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts.

T1016
System Network Configuration Discovery
GroupStealth Falcon

Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim.

T1016
System Network Configuration Discovery
GroupChimera

Chimera has used ipconfig, Ping, and tracert to enumerate the IP address and network environment and settings of the local host.

T1016
System Network Configuration Discovery
GroupMirrorFace

MirrorFace has used ipconfig for reconnaissance.

T1016
System Network Configuration Discovery
GroupMedusa Group

Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.

T1016
System Network Configuration Discovery
GroupDarkhotel

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1016
System Network Configuration Discovery
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information.

T1016
System Network Configuration Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.

T1016
System Network Configuration Discovery
GroupEarth Lusca

Earth Lusca used the command ipconfig to obtain information about network configurations.

T1016
System Network Configuration Discovery
GroupWizard Spider

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.

T1016
System Network Configuration Discovery
GroupMoonstone Sleet

Moonstone Sleet has gathered information on victim network configuration.

T1016
System Network Configuration Discovery
GroupPlay

Play has used the information-stealing tool Grixba to enumerate network information.

T1016
System Network Configuration Discovery
GroupHEXANE

HEXANE has used Ping and `tracert` for network discovery.

T1016
System Network Configuration Discovery
GroupMagic Hound

Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address.

T1016
System Network Configuration Discovery
GroupThreat Group-3390

Threat Group-3390 actors use NBTscan to discover vulnerable systems.

T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016
System Network Configuration Discovery
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

T1016
System Network Configuration Discovery
GroupShinyHunters

ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.