1200KM / detection
T1049 System Network Connections Discovery — Detection Rules
Detection workspace for T1049 System Network Connections Discovery: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- System Network Connections Discovery - Linux · test · low · {"category":"process_creation","product":"linux"}
- System Network Connections Discovery - MacOs · test · informational · {"category":"process_creation","product":"macos"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- Use Get-NetTCPConnection · test · low · {"product":"windows","category":"ps_classic_start"}
- Use Get-NetTCPConnection - PowerShell Module · test · low · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- HackTool - SharpView Execution · test · high · {"category":"process_creation","product":"windows"}
- System Network Connections Discovery Via Net.EXE · test · low · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0320 Detection of System Network Connections Discovery Across Platforms
AN0903 Analytic 0903
Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections.
AN0904 Analytic 0904
Detects use of netstat, ss, lsof, or custom shell scripts to list current network connections. Often paired with privilege escalation or staging.
AN0905 Analytic 0905
Detects shell-based enumeration of active connections using `netstat`, `lsof -i`, or AppleScript-based system discovery.
AN0906 Analytic 0906
Detects shell or API usage of `esxcli network ip connection list` or `netstat` to enumerate ESXi host connections.
AN0907 Analytic 0907
Detects interactive or automated use of CLI commands like `show ip sockets`, `show tcp brief`, or SNMP queries for active sessions on routers/switches.
AN0908 Analytic 0908
Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- Turla · G0010
- admin@338 · G0018
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Poseidon Group · G0033
- Sandworm Team · G0034
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT38 · G0082
- GALLIUM · G0093
- APT41 · G0096
- Chimera · G0114
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- Andariel · G0138
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- INC Ransom · G1032
- Velvet Ant · G1047
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.