Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
MalwareHDoor | HDoor scans to identify open ports on the victim. |
| T1046 Network Service Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to scan for open ports on hosts in a connected network. |
| T1046 Network Service Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1046 Network Service Discovery |
MalwareBADHATCH | BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| T1046 Network Service Discovery |
MalwareHildegard | Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1046 Network Service Discovery |
MalwareInvisiMole | InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1046 Network Service Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can scan networks for open ports and listening services. |
| T1046 Network Service Discovery |
MalwareLucifer | Lucifer can scan for open ports including TCP ports 135 and 1433. |
| T1046 Network Service Discovery |
MalwareBlackEnergy | BlackEnergy has conducted port scans on a host. |
| T1046 Network Service Discovery |
MalwareConficker | Conficker scans for other machines to infect. |
| T1046 Network Service Discovery |
MalwareChina Chopper | China Chopper's server component can spider authentication portals. |
| T1046 Network Service Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist file`.It also utilizes Apple's CWWiFiClient API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1046 Network Service Discovery |
MalwareRemsec | Remsec has a plugin that can perform ARP scanning as well as port scanning. |
| T1046 Network Service Discovery |
MalwareXbash | Xbash can perform port scanning of TCP and UDP ports. |
| T1046 Network Service Discovery |
MalwareXTunnel | XTunnel is capable of probing the network for open ports. |
| T1046 Network Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a port scanner on a system. |
| T1046 Network Service Discovery |
MalwareRoyal | Royal can scan the network interfaces of targeted systems. |
| T1046 Network Service Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
| T1046 Network Service Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced Port Scanner tool. |
| T1046 Network Service Discovery |
MalwareMgBot | MgBot includes modules for performing HTTP and server service scans. |
| T1046 Network Service Discovery |
MalwareSpeakUp | SpeakUp checks for availability of specific ports on servers. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1046 Network Service Discovery |
MalwareRamsay | Ramsay can scan for systems that are vulnerable to the EternalBlue exploit. |
| T1046 Network Service Discovery |
MalwareZxShell | ZxShell can launch port scans. |
| T1046 Network Service Discovery |
MalwareIndustroyer | Industroyer uses a custom port scanner to map out a network. |
| T1046 Network Service Discovery |
MalwareHermeticWizard | HermeticWizard has the ability to scan ports on a compromised network. |
| T1046 Network Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can scan for open ports on a compromised machine. |
| T1046 Network Service Discovery |
ToolEmpire | Empire can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolFRP | As part of load balancing FRP can set `healthCheck.type = "tcp"` or `healthCheck.type = "http"` to check service status on specific hosts with TCPing or an HTTP request. |
| T1046 Network Service Discovery |
ToolPoshC2 | PoshC2 can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can conduct port scanning against targeted systems. |
| T1046 Network Service Discovery |
ToolPeirates | Peirates can initiate a port scan against a given IP address. |
| T1046 Network Service Discovery |
ToolNBTscan | NBTscan can be used to scan IP networks. |
| T1046 Network Service Discovery |
ToolKoadic | Koadic can scan for open TCP ports on the target network. |
| T1046 Network Service Discovery |
ToolPupy | Pupy has a built-in module for port scanning. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.