T1018 Remote System Discovery — ATT&CK Technique
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, `esxcli network diag ping`. Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment. Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).
Detection coverage (39)
- Linux Remote System Discovery low
- Net.EXE Execution low
- PUA - AdFind Suspicious Execution high
- Macos Remote System Discovery informational
- Cisco Discovery low
- PUA - Adidnsdump Execution low
- DirectorySearcher Powershell Exploitation medium
- Active Directory Computers Enumeration With Get-AdComputer low
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock medium
- HackTool - NetExec Execution high
- Share And Session Enumeration Using Net.EXE low
- Nltest.EXE Execution low
- Renamed AdFind Execution high
- Suspicious Scan Loop Network medium
- Chopper Webshell Process Pattern high
- Webshell Hacking Activity Patterns high
- Webshell Detection With Command Line Keywords high
- Remote System Discovery with Wmic
- Remote System Discovery with Adsisearcher
- Cisco IOS XE Remote Access Probe Burst
- Domain Controller Discovery with Nltest
- Domain Controller Discovery with Wmic
- GetAdComputer with PowerShell
- GetAdComputer with PowerShell Script Block
- GetDomainComputer with PowerShell Script Block
- GetDomainController with PowerShell Script Block
- GetDomainComputer with PowerShell
- GetDomainController with PowerShell
- GetWmiObject Ds Computer with PowerShell Script Block
- GetWmiObject Ds Computer with PowerShell
- Remote System Discovery with Dsquery
- Windows AdFind Exe
- Windows Get-AdComputer Unconstrained Delegation Discovery
- Windows Netspy Network Scanner Execution
- Windows PowerView Constrained Delegation Discovery
- Windows PowerView Unconstrained Delegation Discovery
- Windows PsTools Recon Usage
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Repeated Blocked Connections
Malware using this technique
- MURKYTOP
- TAINTEDSCRIBE
- ROADTools
- BitPaymer
- QakBot
- USBferry
- Bazar
- BADHATCH
- BlackCat
- Net
- Black Basta
- LODEINFO
- yty
- njRAT
- Industroyer
- Remsec
- Gomir
- CrackMapExec
- PoetRAT
- Nltest
- RansomHub
- Epic
- Kwampirs
- FunnyDream
- Comnie
- WannaCry
- Sykipot
- Cobalt Strike
- SILENTTRINITY
- BloodHound
- DRATzarus
- OSInfo
- Flagpro
- HermeticWizard
- Ping
- Conti
- RATANKBA
- SHOTPUT
- MgBot
- DUSTTRAP
- Carbon
- Kinsing
- Diavol
- TrickBot
- SpicyOmelette
- Arp
- NBTscan
- Olympic Destroyer
- Qilin
- AdFind
Threat actors using this technique
- Chimera
- HAFNIUM
- Conti
- Ember Bear
- APT10
- Fox Kitten
- BlackByte
- FIN8
- Agrius
- Naikon
- Deep Panda
- Earth Lusca
- APT41
- FIN5
- Volt Typhoon
- Sandworm Team
- Play Ransomware
- Mustang Panda
- Akira
- APT15
- HEXANE
- MirrorFace
- APT27
- APT3
- ToddyCat
- Lotus Blossom
- BRONZE BUTLER
- APT39
- APT32
- Silence
- FIN6
- Evil Corp
- Turla
- Rocke
- Leafminer
- GALLIUM
- APT35
- Scattered Spider
- Medusa Ransomware
- Dragonfly