System Network Configuration Discovery

T1016

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.

Adversaries may also leverage a Network Device CLI on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. show ip route, show ip interface). On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address.

Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.

Detection rules22

Rules on DetectionCode tagged with T1016 or one of its sub-techniques.

Sigma9

RuleLevelLog sourceTechnique
OpenCanary - SNMP OID Requesthighopencanary / applicationT1016
Potential Recon Activity Via Nltest.EXEmediumwindows / process_creationT1016
Suspicious Network Connection to IP Lookup Service APIsmediumwindows / network_connectionT1016
Cisco Discoverylowcisco / NULLT1016
Firewall Configuration Discovery Via Netsh.EXElowwindows / process_creationT1016
Nltest.EXE Executionlowwindows / process_creationT1016
Suspicious Network Commandlowwindows / process_creationT1016
System Network Discovery - Linuxinformationallinux / process_creationT1016
System Network Discovery - macOSinformationalmacos / process_creationT1016

Splunk13

RuleTypeRiskData sourceTechnique
Cisco IOS XE Reconnaissance Command ActivityAnomalyNULLCisco IOS LogsT1016
Cisco NVM - Suspicious Network Connection to IP Lookup Service APIAnomalyNULLCisco Network Visibility Module Flow DataT1016
Detect processes used for System Network Configuration DiscoveryTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1016
Linux Auditd System Network Configuration DiscoveryAnomalyNULLLinux Auditd SyscallT1016
Linux System Network DiscoveryAnomalyNULLSysmon for Linux EventID 1, Osquery ResultsT1016
MacOS List Firewall RulesAnomalyNULLOsquery ResultsT1016
Network Discovery Using Route Windows AppHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1016.001
Potential System Network Configuration Discovery ActivityAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1016
Windows Common Abused Cmd Shell Risk BehaviorCorrelationNULLT1016
Windows Post Exploitation Risk BehaviorCorrelationNULLT1016
Windows PowerShell Invoke-RestMethod IP Information CollectionAnomalyNULLPowershell Script Block Logging 4104T1016
Windows System Network Config Discovery Display DNSAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1016
Windows WinPEAS PowerShell Script ExecutionTTPNULLPowershell Script Block Logging 4104T1016

Sub-techniques2

IDNameExamples
T1016.001Internet Connection Discovery26
T1016.002Wi-Fi Discovery7

Groups44

Show 20 more

Software232

Show 208 more
BOLDMOVEBonadanBoxCaonBrave PrinceCalistoCanisterWormCarbonCatchamasCaterpillar WebShellcd00rCharmPowerChrommmeClamblingCobalt StrikeComnieContiCrackMapExecCreepySnailCrimsonCubaCyclops BlinkDEADEYEDenisDiavoldown_newDtrackDuquDUSTTRAPDyreEKANSEliseEmissaryEmpireEpicevilginx2ExplosiveFALLCHILLFatDukeFelismusFELIXROOTFlagproFunnyDreamGeminiDukeGoldMaxGomirGootloaderGrandoreiroGravityRATGreen LambertGrimAgentHavocHexEval LoaderHotCroissantHydraqIceAppleIcedIDifconfigiKittenIndustroyerInvisibleFerretInvisiMoleipconfigIxesheJ-magicJHUHUGITJPINjRATKazuarKesselKevinKeyBoyKEYMARBLEKoadicKobalosKONNIKOPILUWAKKwampirsLAMEHUGLatrodectusLightNeuronLiteDukeLizarLODEINFOLokibotLoudMinerLuciferLunarLoaderLunarWebMacheteMacMaMafaldaMagicRATManjusakaMilanMini Shai-HuludMis-TypeMoonWindMore_eggsMosquitoNaidNanHaiShuNanoCoreNBTscannbtstatNeoichorNETWIRENGLiteNightdoorNinjaNltestNOKKIOceanSaltOctopusOkrumOlympic DestroyerOrzOSInfoOSX_OCEANLOTUS.DPay2KeyPcSharePenquinPikabotPingPullPipeMonPisloaderPLAINTEEPlugXPoshC2PowerDukePowerShowerPOWERSTATSPOWRUNERPrikormkaProxysvcPUBLOADPupyPysaQakBotQilinQUADAGENTQuasarRATQUIETCANARYRamsayRATANKBAReaverRedLeavesRedLine StealerRemsecRevenge RATRifdoorRising SunRogueRobinrouteRoyalRyukS-TypeSagerunexSaint BotSardonicSDBbotShadowPadShamoonSHARPSTATSShimRatReporterShrinkLockerSibotSideTwistSliverSmall SieveSocGholishSoreFangSpeakUpSpicyOmeletteSquirrelwaffleSTARWHALEStrongPityStuxnetSUNBURSTSykipotSys10SysUpdateT9000TaidoorTajMahalTeamPCP Cloud StealerTorismaTrickBotTrojan.KaraganyTroll StealerTSCookieTurianUnknown LoggerUPPERCUTUSBferryValakVERMINVolgmerWannaCryWellMailWellMessWoody RATXbashxCaonXORIndex LoaderytyZebrocyZeroTzwShell

Campaigns13

Procedure examples289

Groups44

Used byProcedure example
Groupadmin@338

admin@338 actors used the following command after exploiting a machine with LOWBALL malware to acquire information about local networks: ipconfig /all >> %temp%\download

GroupAPT1

APT1 used the ipconfig /all command to gather network configuration information.

GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine.

GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

GroupAPT32

APT32 used the ipconfig /all command to gather the IP address from the system.

GroupAPT41

APT41 collected MAC addresses from victim machines.

GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information.

GroupBlackByte

BlackByte used tools such as Arp to pull system network information and identify connected devices.

View all 44 groups examples

Software232

Used byProcedure example
MalwareAction RAT

Action RAT has the ability to collect the MAC address of an infected host.

ToolAdFind

AdFind can extract subnet information from Active Directory.

MalwareAgent Tesla

Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.

MalwareAgent.btz

Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file.

MalwareAmadey

Amadey can identify the IP address of a victim machine.

MalwareAnchor

Anchor can determine the public IP and location of a compromised host.

MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

View all 232 software examples

Campaigns13

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary configured Claude Code to identify and gather system configurations of discovered devices.

CampaignC0015

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

CampaignC0017

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

CampaignC0018

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.

CampaignFunnyDream

During FunnyDream, the threat actors used ipconfig for discovery on remote systems.

CampaignKV Botnet Activity

KV Botnet Activity gathers victim IP information during initial installation stages.

View all 13 campaigns examples

References3

  1. Mandiant APT41 Global Intrusion Open source
    Gyler, C.,Perez D.,Jones, S.,Miller, S.. (2021, February 25). This is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits. Retrieved February 17, 2022.
  2. Trellix Rnasomhouse 2024 Open source
    Pham Duy Phuc, Max Kersten, Noël Keijzer, and Michaël Schrijver. (2024, February 14). RansomHouse am See. Retrieved March 26, 2025.
  3. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.