ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1018×

54 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareTrickBot

TrickBot can enumerate computers and network devices.

T1018
Remote System Discovery
MalwareMURKYTOP

MURKYTOP has the capability to identify remote hosts on connected networks.

T1018
Remote System Discovery
Malwareyty

yty uses the net view command for discovery.

T1018
Remote System Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments.

T1018
Remote System Discovery
MalwareRansomHub

RansomHub can enumerate all accessible machines from the infected system.

T1018
Remote System Discovery
MalwareHavoc

Havoc features a module capable of host enumeration.

T1018
Remote System Discovery
MalwareGomir

Gomir probes arbitrary network endpoints for TCP connectivity.

T1018
Remote System Discovery
MalwareOlympic Destroyer

Olympic Destroyer uses Windows Management Instrumentation to enumerate all systems in the network.

T1018
Remote System Discovery
MalwareDUSTTRAP

DUSTTRAP can use `ping` to identify remote hosts within the victim network.

T1018
Remote System Discovery
MalwareBADHATCH

BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer.

T1018
Remote System Discovery
MalwareConti

Conti has the ability to discover hosts on a target network.

T1018
Remote System Discovery
MalwareDiavol

Diavol can use the ARP table to find remote hosts to scan.

T1018
Remote System Discovery
MalwareBlackCat

BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks.

T1018
Remote System Discovery
MalwareDRATzarus

DRATzarus can search for other machines connected to compromised host and attempt to map the network.

T1018
Remote System Discovery
MalwareSHOTPUT

SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain.

T1018
Remote System Discovery
MalwareFlagpro

Flagpro has been used to execute net view on a targeted system.

T1018
Remote System Discovery
MalwareSpicyOmelette

SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments.

T1018
Remote System Discovery
MalwareRemsec

Remsec can ping or traceroute a remote host.

T1018
Remote System Discovery
MalwareSykipot

Sykipot may use net view /domain to display hostnames of available systems on a network.

T1018
Remote System Discovery
MalwareEpic

Epic uses the net view command on the victim’s machine.

T1018
Remote System Discovery
MalwareUSBferry

USBferry can use net view to gather information about remote systems.

T1018
Remote System Discovery
MalwareWannaCry

WannaCry scans its local network segment for remote systems to try to exploit and copy itself to.

T1018
Remote System Discovery
MalwareLODEINFO

LODEINFO can run `net view` and `net view /domain` for network discovery.

T1018
Remote System Discovery
MalwareTAINTEDSCRIBE

The TAINTEDSCRIBE command and execution module can perform target system enumeration.

T1018
Remote System Discovery
MalwareShamoon

Shamoon scans the C-class subnet of the IPs on the victim's interfaces.

T1018
Remote System Discovery
MalwareBlack Basta

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.

T1018
Remote System Discovery
MalwareBazar

Bazar can enumerate remote systems using Net View.

T1018
Remote System Discovery
MalwareRATANKBA

RATANKBA runs the net view /domain and net view commands.

T1018
Remote System Discovery
MalwareMgBot

MgBot includes modules for performing ARP scans of local connected systems.

T1018
Remote System Discovery
MalwareCobalt Strike

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1018
Remote System Discovery
MalwareCarbon

Carbon uses the net view command.

T1018
Remote System Discovery
MalwareFunnyDream

FunnyDream can collect information about hosts on the victim network.

T1018
Remote System Discovery
MalwareKwampirs

Kwampirs collects a list of available servers with the command net view.

T1018
Remote System Discovery
MalwarePoetRAT

PoetRAT used Nmap for remote system discovery.

T1018
Remote System Discovery
MalwareKinsing

Kinsing has used a script to parse files like /etc/hosts and SSH known_hosts to discover remote systems.

T1018
Remote System Discovery
MalwarenjRAT

njRAT can identify remote hosts on connected networks.

T1018
Remote System Discovery
MalwareQilin

Qilin can enumerate domain-connected hosts during its discovery phase.

T1018
Remote System Discovery
MalwareIndustroyer

Industroyer can enumerate remote computers in the compromised network.

T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1018
Remote System Discovery
MalwareComnie

Comnie runs the net view command

T1018
Remote System Discovery
MalwareOSInfo

OSInfo performs a connection test to discover remote systems in the network

T1018
Remote System Discovery
MalwareBitPaymer

BitPaymer can use net view to discover remote systems.

T1018
Remote System Discovery
MalwareHermeticWizard

HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.`

T1018
Remote System Discovery
ToolNet

Commands such as net view can be used in Net to gather information about available remote systems.

T1018
Remote System Discovery
ToolBloodHound

BloodHound can enumerate and collect the properties of domain computers, including domain controllers.

T1018
Remote System Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate and collect the properties of domain computers.

T1018
Remote System Discovery
ToolArp

Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems.

T1018
Remote System Discovery
ToolROADTools

ROADTools can enumerate Azure AD systems and devices.

T1018
Remote System Discovery
ToolNltest

Nltest may be used to enumerate remote domain controllers using options such as /dclist and /dsgetdc.

T1018
Remote System Discovery
ToolNBTscan

NBTscan can list NetBIOS computer names.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.