1200KM / simulation
T1016 System Network Configuration Discovery — Attack Simulation
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. Adversaries may also leverage a Network Device CLI on network devices to gather information about…
Technique description
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. Adversaries may also leverage a Network Device CLI on network devices to gather information about…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- List Windows Firewall Rules
Procedure 038263cb-00f4-4b0a-98ae-0696c67e1752; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Qakbot Recon
Procedure 121de5c6-5818-4868-b8a7-8fd07c455c1b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DNS Server Discovery Using nslookup
Procedure 34557863-344a-468f-808b-a1bfb89b4fa9; elevation not declared required; cleanup not declared. Not executed or individually validated.
- List Open Egress Ports
Procedure 4b467538-f102-491d-ace7-ed487b853bf5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- IPv4 Enumeration with GetIpAddrTable
Procedure 7dd47911-b7b9-48c2-bb2c-8e1fad5d6d99; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Configuration Discovery on Windows
Procedure 970ab6a1-0157-4f3f-9a73-ec4166754b23; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Adfind - Enumerate Active Directory Subnet Objects
Procedure 9bb45dd7-c466-4f93-83a1-be30e56033ee; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Configuration Discovery
Procedure c141bbdb-7fca-4254-9fd6-f47e79447e17; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Configuration Discovery (TrickBot Style)
Procedure dafaf052-5508-402d-bf77-51e0700c02e2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- List macOS Firewall Rules
Procedure ff1d8c25-2aa4-4f18-a425-fede4a41ee88; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
- AdFind · S0552
- Arp · S0099
- AsyncRAT · S1087
- Cobalt Strike · S0154
- CrackMapExec · S0488
- Empire · S0363
- evilginx2 · S9003
- ifconfig · S0101
- ipconfig · S0100
- Koadic · S0250
- NBTscan · S0590
- nbtstat · S0102
- Nltest · S0359
- PcShare · S1050
- PoshC2 · S0378
- Pupy · S0192
- QuasarRAT · S0262
- route · S0103
- ShimRatReporter · S0445
- Sliver · S0633
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- Naikon · G0019
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Dragonfly · G0035
- Stealth Falcon · G0038
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- SideCopy · G1008
- Moses Staff · G1009
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- Moonstone Sleet · G1036
- Play · G1040
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.