1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1016 System Network Configuration Discovery — Detection Rules

Detection workspace for T1016 System Network Configuration Discovery: 9 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0195 Behavioral Detection of System Network Configuration Discovery

AN0559 Analytic 0559

Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.

AN0560 Analytic 0560

Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration.

AN0561 Analytic 0561

Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status.

AN0562 Analytic 0562

Use of `esxcli network` commands (e.g., `esxcli network nic list`, `esxcli network ip interface ipv4 get`) via SSH or hostd to enumerate adapter and IP information.

AN0563 Analytic 0563

CLI-based execution of interface and routing discovery commands (e.g., `show ip interface`, `show arp`, `show route`) over Telnet, SSH, or console.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1016 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.