1200KM / detection
T1016 System Network Configuration Discovery — Detection Rules
Detection workspace for T1016 System Network Configuration Discovery: 9 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - SNMP OID Request · test · high · {"category":"application","product":"opencanary"}
- System Network Discovery - Linux · test · informational · {"category":"process_creation","product":"linux"}
- System Network Discovery - macOS · test · informational · {"product":"macos","category":"process_creation"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- Suspicious Network Connection to IP Lookup Service APIs · test · medium · {"category":"network_connection","product":"windows"}
- Firewall Configuration Discovery Via Netsh.EXE · test · low · {"category":"process_creation","product":"windows"}
- Nltest.EXE Execution · test · low · {"category":"process_creation","product":"windows"}
- Potential Recon Activity Via Nltest.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Network Command · test · low · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0195 Behavioral Detection of System Network Configuration Discovery
AN0559 Analytic 0559
Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.
AN0560 Analytic 0560
Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration.
AN0561 Analytic 0561
Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status.
AN0562 Analytic 0562
Use of `esxcli network` commands (e.g., `esxcli network nic list`, `esxcli network ip interface ipv4 get`) via SSH or hostd to enumerate adapter and IP information.
AN0563 Analytic 0563
CLI-based execution of interface and routing discovery commands (e.g., `show ip interface`, `show arp`, `show route`) over Telnet, SSH, or console.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- AdFind · S0552
- Arp · S0099
- AsyncRAT · S1087
- Cobalt Strike · S0154
- CrackMapExec · S0488
- Empire · S0363
- evilginx2 · S9003
- ifconfig · S0101
- ipconfig · S0100
- Koadic · S0250
- NBTscan · S0590
- nbtstat · S0102
- Nltest · S0359
- PcShare · S1050
- PoshC2 · S0378
- Pupy · S0192
- QuasarRAT · S0262
- route · S0103
- ShimRatReporter · S0445
- Sliver · S0633
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- Naikon · G0019
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Stealth Falcon · G0038
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- SideCopy · G1008
- Moses Staff · G1009
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- Moonstone Sleet · G1036
- Play · G1040
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.