Remote System Discovery

T1018

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, `esxcli network diag ping`.

Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.

Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).

Detection rules39

Rules on DetectionCode tagged with T1018.

Sigma16

RuleLevelLog source
Chopper Webshell Process Patternhighwindows / process_creation
HackTool - NetExec Executionhighwindows / process_creation
PUA - AdFind Suspicious Executionhighwindows / process_creation
Renamed AdFind Executionhighwindows / process_creation
Webshell Detection With Command Line Keywordshighwindows / process_creation
Webshell Hacking Activity Patternshighwindows / process_creation
DirectorySearcher Powershell Exploitationmediumwindows / ps_script
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlockmediumwindows / ps_script
Suspicious Scan Loop Networkmediumwindows / process_creation
Active Directory Computers Enumeration With Get-AdComputerlowwindows / ps_script
Cisco Discoverylowcisco / NULL
Linux Remote System Discoverylowlinux / process_creation
Nltest.EXE Executionlowwindows / process_creation
PUA - Adidnsdump Executionlowwindows / process_creation
Share And Session Enumeration Using Net.EXElowwindows / process_creation

Splunk23

RuleTypeRiskData source
Cisco IOS XE Remote Access Probe BurstAnomalyNULLCisco IOS Logs
Cisco Secure Firewall - Blocked ConnectionAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Cisco Secure Firewall - Repeated Blocked ConnectionsAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Domain Controller Discovery with NltestTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Controller Discovery with WmicHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetAdComputer with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetAdComputer with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
GetDomainComputer with PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetDomainComputer with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
GetDomainController with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetDomainController with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
GetWmiObject Ds Computer with PowerShellAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetWmiObject Ds Computer with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
Remote System Discovery with AdsisearcherTTPNULLPowershell Script Block Logging 4104
Remote System Discovery with DsqueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups41

Show 17 more

Software54

Show 30 more

Campaigns9

Procedure examples104

Groups41

Used byProcedure example
GroupAgrius

Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments.

GroupAkira

Akira uses software such as Advanced IP Scanner and MASSCAN to identify remote hosts within victim networks.

GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

GroupAPT32

APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.

GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

GroupAPT41

APT41 has used MiPing to discover active systems in the victim network.

GroupBlackByte

BlackByte used tools such as Arp to identify remotely-connected devices.

GroupBRONZE BUTLER

BRONZE BUTLER typically use ping and Net to enumerate systems.

View all 41 groups examples

Software54

Used byProcedure example
ToolAdFind

AdFind has the ability to query Active Directory for computers.

ToolArp

Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems.

MalwareBackdoor.Oldrea

Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments.

MalwareBADHATCH

BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer.

MalwareBazar

Bazar can enumerate remote systems using Net View.

MalwareBitPaymer

BitPaymer can use net view to discover remote systems.

MalwareBlack Basta

Black Basta can use LDAP queries to connect to AD and iterate over connected workstations.

MalwareBlackCat

BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks.

View all 54 software examples

Campaigns9

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.

Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team checked for connectivity to resources within the network and used LDAP to query Active Directory, discovering information about computers listed in AD.

CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

CampaignFunnyDream

During FunnyDream, the threat actors used several tools and batch files to map victims' internal networks.

CampaignLeviathan Australian Intrusions

Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

CampaignOperation Wocao

During Operation Wocao, threat actors used `nbtscan` and `ping` to discover remote systems, as well as `dsquery subnet` on a domain controller to retrieve all subnets in the Active Directory.

View all 9 campaigns examples

References2

  1. CISA AR21-126A FIVEHANDS May 2021 Open source
    CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.
  2. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.