System Network Connections Discovery

T1049

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of discovery techniques depending on the operating system, but the resulting information may include details about the networked cloud environment relevant to the adversary's goals. Cloud providers may have different ways in which their virtual networks operate. Similarly, adversaries who gain access to network devices may also perform similar discovery activities to gather information about connected systems and services.

Utilities and commands that acquire this information include netstat, "net use," and "net session" with Net. In Mac and Linux, netstat and lsof can be used to list current connections. who -a and w can be used to show which users are currently logged in, similar to "net session". Additionally, built-in features native to network devices and Network Device CLI may be used (e.g. show ip sockets, show tcp brief). On ESXi servers, the command `esxi network ip connection list` can be used to list active network connections.

Detection rules16

Rules on DetectionCode tagged with T1049.

Sigma7

RuleLevelLog source
HackTool - SharpView Executionhighwindows / process_creation
Cisco Discoverylowcisco / NULL
System Network Connections Discovery - Linuxlowlinux / process_creation
System Network Connections Discovery Via Net.EXElowwindows / process_creation
Use Get-NetTCPConnectionlowwindows / ps_classic_start
Use Get-NetTCPConnection - PowerShell Modulelowwindows / ps_module
System Network Connections Discovery - MacOsinformationalmacos / process_creation

Splunk9

RuleTypeRiskData source
GetNetTcpconnection with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetNetTcpconnection with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Network Connection Discovery With ArpHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Network Connection Discovery With NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Network Connection Discovery With NetstatHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Common Abused Cmd Shell Risk BehaviorCorrelationNULL
Windows Network Connection Discovery Via NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Post Exploitation Risk BehaviorCorrelationNULL
Windows System Network Connections Discovery NetshAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups32

Show 8 more

Software61

Show 37 more

Campaigns5

Procedure examples98

Groups32

Used byProcedure example
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: netstat -ano >> %temp%\download

GroupAndariel

Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.

GroupAPT1

APT1 used the net use command to get a listing on network connections.

GroupAPT3

APT3 has a tool that can enumerate current network connections.

GroupAPT32

APT32 used the netstat -anpo tcp command to display TCP connections on the victim's machine.

GroupAPT38

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

GroupAPT5

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

View all 32 groups examples

Software61

Used byProcedure example
MalwareAria-body

Aria-body has the ability to gather TCP and UDP table status listings.

MalwareBabuk

Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption.

MalwareBADHATCH

BADHATCH can execute `netstat.exe -f` on a compromised machine.

MalwareBlackEnergy

BlackEnergy has gathered information about local network connections using netstat.

MalwareCarbon

Carbon uses the netstat -r and netstat -an commands.

MalwareCobalt Strike

Cobalt Strike can produce a sessions report from compromised hosts.

MalwareComnie

Comnie executes the netstat -ano command.

MalwareConti

Conti can enumerate routine network connections from a compromised host.

View all 61 software examples

Campaigns5

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to map internal network architecture and access relationships.

CampaignFunnyDream

During FunnyDream, the threat actors used netstat to discover network connections on remote systems.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance.

CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of open connections on the infected system using `netstat` and checks whether it has an internet connection.

References5

  1. Amazon AWS VPC Guide Open source
    Amazon. (n.d.). What Is Amazon VPC?. Retrieved October 6, 2019.
  2. Google VPC Overview Open source
    Google. (2019, September 23). Virtual Private Cloud (VPC) network overview. Retrieved October 6, 2019.
  3. Microsoft Azure Virtual Network Overview Open source
    Annamalai, N., Casey, C., Almeida, M., et. al.. (2019, June 18). What is Azure Virtual Network?. Retrieved October 6, 2019.
  4. Sygnia ESXi Ransomware 2025 Open source
    Zhongyuan Hau (Aaron), Ren Jie Yow, and Yoav Mazor. (2025, January 21). ESXi Ransomware Attacks: Stealthy Persistence through. Retrieved March 27, 2025.
  5. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.