1200KM / simulation
T1049 System Network Connections Discovery — Attack Simulation
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of…
Technique description
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- System Network Connections Discovery
Procedure 0940a971-809a-48f1-9c4d-b1d785e96ee5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Discovery using SharpView
Procedure 96f974bb-a0da-4d87-a744-ff33e73367e9; elevation required; cleanup not declared. Not executed or individually validated.
- System Network Connections Discovery via sockstat (Linux, FreeBSD)
Procedure 997bb0a6-421e-40c7-b5d2-0f493904ef9b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Connections Discovery FreeBSD, Linux & MacOS
Procedure 9ae28d3f-190f-4fa0-b023-c7bd3e0eabf2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Connections Discovery via PowerShell (Process Mapping)
Procedure b52c8233-8f71-4bd7-9928-49fec8215cf5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Connections Discovery via ss or lsof (Linux/MacOS)
Procedure bcf05343-ef1d-4052-8a27-b00c9be42b9f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Network Connections Discovery with PowerShell
Procedure f069f0f1-baad-4831-aa2b-eddac4baac4a; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- Turla · G0010
- admin@338 · G0018
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Poseidon Group · G0033
- Sandworm Team · G0034
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT38 · G0082
- GALLIUM · G0093
- APT41 · G0096
- Chimera · G0114
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- Andariel · G0138
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- INC Ransom · G1032
- Velvet Ant · G1047
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.