1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1049 System Network Connections Discovery — Detection Rules

Detection workspace for T1049 System Network Connections Discovery: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0320 Detection of System Network Connections Discovery Across Platforms

AN0903 Analytic 0903

Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections.

AN0904 Analytic 0904

Detects use of netstat, ss, lsof, or custom shell scripts to list current network connections. Often paired with privilege escalation or staging.

AN0905 Analytic 0905

Detects shell-based enumeration of active connections using `netstat`, `lsof -i`, or AppleScript-based system discovery.

AN0906 Analytic 0906

Detects shell or API usage of `esxcli network ip connection list` or `netstat` to enumerate ESXi host connections.

AN0907 Analytic 0907

Detects interactive or automated use of CLI commands like `show ip sockets`, `show tcp brief`, or SNMP queries for active sessions on routers/switches.

AN0908 Analytic 0908

Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1049 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.