EXPLORE
← Back to Explore
T1016

System Network Configuration Discovery

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include [Arp](https://attack.mitre.org/software/S0099), [ipconfig](https://attack.mitre.org/software/S0100)/[ifconfig](https://attack.mitre.org/software/S0101), [nbtstat](https://attack.mitre.org/softwar...

ESXiLinuxmacOSNetwork DevicesWindows
39
Detections
3
Sources
43
Threat Actors

BY SOURCE

19elastic10sigma10splunk_escu

PROCEDURES (23)

Process Creation Monitoring4 detections

Auto-extracted: 4 detections for process creation monitoring

General Monitoring4 detections

Auto-extracted: 4 detections for general monitoring

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Dns2 detections

Auto-extracted: 2 detections for dns

Remote2 detections

Auto-extracted: 2 detections for remote

Child Process2 detections

Auto-extracted: 2 detections for child process

Child Process2 detections

Auto-extracted: 2 detections for child process

Service1 detections

Auto-extracted: 1 detections for service

Service1 detections

Auto-extracted: 1 detections for service

Powershell1 detections

Auto-extracted: 1 detections for powershell

Lateral1 detections

Auto-extracted: 1 detections for lateral

Credential1 detections

Auto-extracted: 1 detections for credential

Remote1 detections

Auto-extracted: 1 detections for remote

Network Connection Monitoring1 detections

Auto-extracted: 1 detections for network connection monitoring

Service1 detections

Auto-extracted: 1 detections for service

Api1 detections

Auto-extracted: 1 detections for api

Unusual1 detections

Auto-extracted: 1 detections for unusual

Lateral1 detections

Auto-extracted: 1 detections for lateral

Privilege1 detections

Auto-extracted: 1 detections for privilege

Credential1 detections

Auto-extracted: 1 detections for credential

Privilege1 detections

Auto-extracted: 1 detections for privilege

C21 detections

Auto-extracted: 1 detections for c2

C21 detections

Auto-extracted: 1 detections for c2

DETECTIONS (39)

Active Directory Discovery using AdExplorer
elasticlow
AdFind Command Activity
elasticlow
Cisco Discovery
sigmalow
Cisco NVM - Suspicious Network Connection to IP Lookup Service API
splunk_escu
Discovery Command Output Written to Suspicious File
elasticmedium
DNS Enumeration Detected via Defend for Containers
elasticlow
DNS Request for IP Lookup Service via Unsigned Binary
elasticmedium
Enumeration Command Spawned via WMIPrvSE
elasticlow
External IP Address Discovery via Curl
elasticlow
Firewall Configuration Discovery Via Netsh.EXE
sigmalow
Linux Auditd System Network Configuration Discovery
splunk_escu
Linux System Network Discovery
splunk_escu
Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet
sigmalow
MacOS List Firewall Rules
splunk_escu
Nltest.EXE Execution
sigmalow
OpenCanary - SNMP OID Request
sigmahigh
Potential Meterpreter Reverse Shell
elastichigh
Potential Recon Activity Via Nltest.EXE
sigmamedium
Potential System Network Configuration Discovery Activity
splunk_escu
PowerShell Suspicious Discovery Related Windows API Functions
elasticlow
Suspicious Instance Metadata Service (IMDS) API Command Line Execution
elasticmedium
Suspicious Instance Metadata Service (IMDS) API Request
elasticmedium
Suspicious JetBrains TeamCity Child Process
elasticmedium
Suspicious MS Office Child Process
elasticmedium
Suspicious Network Command
sigmalow
Suspicious Network Connection to IP Lookup Service APIs
sigmamedium
Suspicious PDF Reader Child Process
elasticlow
Suspicious System Commands Executed by Previously Unknown Executable
elasticlow
System and Network Configuration Check
elasticmedium
System Network Discovery - Linux
sigmainformational
System Network Discovery - macOS
sigmainformational
System Public IP Discovery via DNS Query
elastichigh
Unusual Linux Network Configuration Discovery
elasticlow
Windows Common Abused Cmd Shell Risk Behavior
splunk_escu
Windows Post Exploitation Risk Behavior
splunk_escu
Windows PowerShell Invoke-RestMethod IP Information Collection
splunk_escu
Windows System Network Config Discovery Display DNS
splunk_escu
Windows WinPEAS PowerShell Script Execution
splunk_escu
Wireless Credential Dumping using Netsh Command
elastichigh