ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1049×

61 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
MalwareTorisma

Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections.

T1049
System Network Connections Discovery
MalwarePOWRUNER

POWRUNER may collect active network connections by running netstat -an on a victim.

T1049
System Network Connections Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections.

T1049
System Network Connections Discovery
MalwareSardonic

Sardonic has the ability to execute the `netstat` command.

T1049
System Network Connections Discovery
MalwareRedLeaves

RedLeaves can enumerate drives and Remote Desktop sessions.

T1049
System Network Connections Discovery
MalwareGravityRAT

GravityRAT uses the netstat command to find open ports on the victim’s machine.

T1049
System Network Connections Discovery
MalwareNETWIRE

NETWIRE can capture session logon details from a compromised host.

T1049
System Network Connections Discovery
MalwarePyDCrypt

PyDCrypt has used netsh to find RPC connections on remote machines.

T1049
System Network Connections Discovery
MalwareAria-body

Aria-body has the ability to gather TCP and UDP table status listings.

T1049
System Network Connections Discovery
MalwareBADHATCH

BADHATCH can execute `netstat.exe -f` on a compromised machine.

T1049
System Network Connections Discovery
MalwarePUBLOAD

PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather information on network connections.

T1049
System Network Connections Discovery
MalwareMafalda

Mafalda can use the GetExtendedTcpTable function to retrieve information about established TCP connections.

T1049
System Network Connections Discovery
MalwareVolgmer

Volgmer can gather information about TCP connection state.

T1049
System Network Connections Discovery
MalwareOkrum

Okrum was seen using NetSess to discover NetBIOS sessions.

T1049
System Network Connections Discovery
MalwareConti

Conti can enumerate routine network connections from a compromised host.

T1049
System Network Connections Discovery
MalwareLucifer

Lucifer can identify the IP and port numbers for all remote connections from the compromised host.

T1049
System Network Connections Discovery
MalwareBlackEnergy

BlackEnergy has gathered information about local network connections using netstat.

T1049
System Network Connections Discovery
MalwareSHOTPUT

SHOTPUT uses netstat to list TCP connection status.

T1049
System Network Connections Discovery
MalwareFlagpro

Flagpro has been used to execute netstat -ano on a compromised host.

T1049
System Network Connections Discovery
MalwareBabuk

Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption.

T1049
System Network Connections Discovery
MalwarePlugX

PlugX has a module for enumerating TCP and UDP network connections and associated processes using the netstat command.

T1049
System Network Connections Discovery
MalwareRemsec

Remsec can obtain a list of active connections and open ports.

T1049
System Network Connections Discovery
MalwareSykipot

Sykipot may use netstat -ano to display active network connections.

T1049
System Network Connections Discovery
MalwareEpic

Epic uses the net use, net session, and netstat commands to gather information on network connections.

T1049
System Network Connections Discovery
MalwareCuba

Cuba can use the function GetIpNetTable to recover the last connections to the victim's machine.

T1049
System Network Connections Discovery
MalwareUSBferry

USBferry can use netstat and nbtstat to detect active network connections.

T1049
System Network Connections Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use netstat to collect a list of network connections.

T1049
System Network Connections Discovery
MalwareKONNI

KONNI has used net session on the victim's machine.

T1049
System Network Connections Discovery
MalwareSibot

Sibot has retrieved a GUID associated with a present LAN connection on a compromised machine.

T1049
System Network Connections Discovery
MalwareMESSAGETAP

After loading the keyword and phone data files, MESSAGETAP begins monitoring all network connections to and from the victim server.

T1049
System Network Connections Discovery
MalwareRATANKBA

RATANKBA uses netstat -ano to search for specific IP address ranges.

T1049
System Network Connections Discovery
MalwareZebrocy

Zebrocy uses netstat -aon to gather network connection information.

T1049
System Network Connections Discovery
MalwareSpeakUp

SpeakUp uses the arp -a command.

T1049
System Network Connections Discovery
MalwareCobalt Strike

Cobalt Strike can produce a sessions report from compromised hosts.

T1049
System Network Connections Discovery
MalwareCarbon

Carbon uses the netstat -r and netstat -an commands.

T1049
System Network Connections Discovery
MalwareRamsay

Ramsay can use netstat to enumerate network connections.

T1049
System Network Connections Discovery
MalwareKwampirs

Kwampirs collects a list of active and listening connections by using the command netstat -nao as well as a list of available network mappings with net use.

T1049
System Network Connections Discovery
MalwareEgregor

Egregor can enumerate all connected drives.

T1049
System Network Connections Discovery
MalwareMaze

Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine.

T1049
System Network Connections Discovery
MalwareLunarWeb

LunarWeb can enumerate system network connections.

T1049
System Network Connections Discovery
MalwareQakBot

QakBot can use netstat to enumerate current network connections.

T1049
System Network Connections Discovery
MalwarejRAT

jRAT can list network connections.

T1049
System Network Connections Discovery
MalwareWaterbear

Waterbear can use API hooks on `GetExtendedTcpTable` to retrieve a table containing a list of TCP endpoints available to the application.

T1049
System Network Connections Discovery
MalwareComnie

Comnie executes the netstat -ano command.

T1049
System Network Connections Discovery
MalwareOSInfo

OSInfo enumerates the current network connections similar to net use .

T1049
System Network Connections Discovery
MalwareLizar

Lizar has a plugin to retrieve information about all active network sessions on the infected server.

T1049
System Network Connections Discovery
MalwareDtrack

Dtrack can collect network and active connection information.

T1049
System Network Connections Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate open ports on a victim machine.

T1049
System Network Connections Discovery
ToolNet

Commands such as net use and net session can be used in Net to gather information about network connections from a particular host.

T1049
System Network Connections Discovery
ToolShimRatReporter

ShimRatReporter used the Windows function GetExtendedUdpTable to detect connected UDP endpoints.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.