T1016 System Network Configuration Discovery — ATT&CK Technique
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. Adversaries may also leverage a Network Device CLI on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. show ip route, show ip interface). On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address. Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.
Detection coverage (23)
- Potential Pikabot Discovery Activity high
- Userdomain Variable Enumeration low
- Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet low
- System Network Discovery - Linux informational
- OpenCanary - SNMP OID Request high
- System Network Discovery - macOS informational
- Cisco Discovery low
- Suspicious Network Connection to IP Lookup Service APIs medium
- Potential Recon Activity Via Nltest.EXE medium
- Firewall Configuration Discovery Via Netsh.EXE low
- Nltest.EXE Execution low
- Suspicious Network Command low
- Cisco IOS XE Reconnaissance Command Activity
- Cisco NVM - Suspicious Network Connection to IP Lookup Service API
- Linux Auditd System Network Configuration Discovery
- Linux System Network Discovery
- MacOS List Firewall Rules
- Potential System Network Configuration Discovery Activity
- Windows Common Abused Cmd Shell Risk Behavior
- Windows Post Exploitation Risk Behavior
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows WinPEAS PowerShell Script Execution
- Windows System Network Config Discovery Display DNS
Malware using this technique
- Chrommme
- ifconfig
- Stuxnet
- Dyre
- Olympic Destroyer
- Koadic
- Pikabot
- T9000
- Lucifer
- IceApple
- BLUELIGHT
- Empire
- VERMIN
- PoshC2
- KeyBoy
- POWRUNER
- PowerDuke
- Sagerunex
- KEYMARBLE
- Cobalt Strike
- NanoCore
- Pysa
- Ramsay
- Sardonic
- GravityRAT
- JHUHUGIT
- Latrodectus
- iKitten
- Emissary
- NBTscan
- PlugX
- Kevin
- Saint Bot
- CreepySnail
- OSX_OCEANLOTUS.D
- KONNI
- Rifdoor
- JPIN
- PcShare
- Troll Stealer
- OceanSalt
- LunarLoader
- AppleSeed
- Agent Tesla
- Milan
- LiteDuke
- Elise
- Calisto
- StrongPity
- Caterpillar WebShell
Threat actors using this technique
- OilRig
- HEXANE
- Mustang Panda
- Play Ransomware
- BlackByte
- Dragonfly
- admin@338
- Earth Lusca
- Lotus Blossom
- Moses Staff
- APT19
- FIN13
- Volt Typhoon
- Lazarus Group
- APT3
- MuddyWater
- APT10
- SideCopy
- Stealth Falcon
- APT1
- Tropic Trooper
- APT27
- APT15
- Scattered Spider
- Naikon
- APT42
- MirrorFace
- Chimera
- APT35
- Sidewinder
- Turla
- Conti
- TeamTNT
- APT41
- GALLIUM
- Moonstone Sleet
- Kimsuky
- Darkhotel
- HAFNIUM
- APT32
- Medusa Ransomware
- Higaisa
- ZIRCONIUM