Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1049 System Network Connections Discovery |
GroupGALLIUM | GALLIUM used |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1049 System Network Connections Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1049 System Network Connections Discovery |
GroupmenuPass | menuPass has used |
| T1049 System Network Connections Discovery |
GroupAPT32 | APT32 used the |
| T1049 System Network Connections Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1049 System Network Connections Discovery |
GroupAndariel | Andariel has used the |
| T1049 System Network Connections Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1049 System Network Connections Discovery |
GroupOilRig | OilRig has used |
| T1049 System Network Connections Discovery |
GroupTropic Trooper | Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1049 System Network Connections Discovery |
GroupAPT1 | APT1 used the |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1049 System Network Connections Discovery |
GroupPoseidon Group | Poseidon Group obtains and saves information about victim network interfaces and addresses. |
| T1049 System Network Connections Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1049 System Network Connections Discovery |
GroupChimera | Chimera has used |
| T1049 System Network Connections Discovery |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports. |
| T1049 System Network Connections Discovery |
GroupToddyCat | ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1049 System Network Connections Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| T1049 System Network Connections Discovery |
GroupLazarus Group | Lazarus Group has used |
| T1049 System Network Connections Discovery |
GroupINC Ransom | INC Ransom has used RDP to test network connections. |
| T1049 System Network Connections Discovery |
GroupEarth Lusca | Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” |
| T1049 System Network Connections Discovery |
GroupVelvet Ant | Velvet Ant has enumerated existing network connections on victim devices. |
| T1049 System Network Connections Discovery |
GroupHEXANE | HEXANE has used netstat to monitor connections to specific ports. |
| T1049 System Network Connections Discovery |
GroupMagic Hound | Magic Hound has used quser.exe to identify existing RDP connections. |
| T1049 System Network Connections Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim. |
| T1049 System Network Connections Discovery |
GroupFIN13 | FIN13 has used `netstat` and other net commands for network reconnaissance efforts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.