ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1018×

41 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupIndrik Spider

Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.

T1018
Remote System Discovery
GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

T1018
Remote System Discovery
GroupGALLIUM

GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as ping to identify remote systems.

T1018
Remote System Discovery
GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

T1018
Remote System Discovery
GroupVolt Typhoon

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1018
Remote System Discovery
GroupAPT41

APT41 has used MiPing to discover active systems in the victim network.

T1018
Remote System Discovery
GroupDragonfly

Dragonfly has likely obtained a list of hosts in the victim environment.

T1018
Remote System Discovery
GroupmenuPass

menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command net view /domain to a PlugX implant to gather information about remote systems on the network.

T1018
Remote System Discovery
GroupAPT32

APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.

T1018
Remote System Discovery
GroupHAFNIUM

HAFNIUM has enumerated domain controllers using `net group "Domain computers"` and `nltest /dclist`.

T1018
Remote System Discovery
GroupNaikon

Naikon has used a netbios scanner for remote machine identification.

T1018
Remote System Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1018
Remote System Discovery
GroupLeafminer

Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems.

T1018
Remote System Discovery
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.

T1018
Remote System Discovery
GroupMustang Panda

Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1018
Remote System Discovery
GroupRocke

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.

T1018
Remote System Discovery
GroupScattered Spider

Scattered Spider can enumerate remote systems, such as VMware vCenter infrastructure.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1018
Remote System Discovery
GroupAkira

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.

T1018
Remote System Discovery
GroupKe3chang

Ke3chang has used network scanning and enumeration tools, including Ping.

T1018
Remote System Discovery
GroupTurla

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1018
Remote System Discovery
GroupFIN5

FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets.

T1018
Remote System Discovery
GroupLotus Blossom

Lotus Blossom has used Ping to identify remote systems.

T1018
Remote System Discovery
GroupChimera

Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment.

T1018
Remote System Discovery
GroupMirrorFace

MirrorFace has used Ping for system discovery.

T1018
Remote System Discovery
GroupMedusa Group

Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.

T1018
Remote System Discovery
GroupBRONZE BUTLER

BRONZE BUTLER typically use ping and Net to enumerate systems.

T1018
Remote System Discovery
GroupDeep Panda

Deep Panda has used ping to identify other machines of interest.

T1018
Remote System Discovery
GroupEmber Bear

Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.

T1018
Remote System Discovery
GroupToddyCat

ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery.

T1018
Remote System Discovery
GroupAgrius

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

T1018
Remote System Discovery
GroupFox Kitten

Fox Kitten has used Angry IP Scanner to detect remote systems.

T1018
Remote System Discovery
GroupEarth Lusca

Earth Lusca used the command powershell “Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list -
property * | findstr “Address””
to find the network information of successfully logged-in accounts to discovery addresses of other machines. Earth Lusca has also used multiple scanning tools to discover other machines within the same compromised network.

T1018
Remote System Discovery
GroupSilence

Silence has used Nmap to scan the corporate network, build a network topology, and identify vulnerable hosts.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1018
Remote System Discovery
GroupPlay

Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.

T1018
Remote System Discovery
GroupHEXANE

HEXANE has used `net view` to enumerate domain machines.

T1018
Remote System Discovery
GroupMagic Hound

Magic Hound has used Ping for discovery on targeted networks.

T1018
Remote System Discovery
GroupThreat Group-3390

Threat Group-3390 has used the net view command.

T1018
Remote System Discovery
GroupFIN8

FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.

T1018
Remote System Discovery
GroupShinyHunters

ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.