Loading the current evidence view. Navigation and account controls remain available.
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
Tactics: discovery
40
known groups
53
software
910
corpus matches
about
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, net view using Net, or, on ESXi servers, esxcli network diag ping.
Adversaries may also analyze data from local host files (ex: C:\Windows\System32\Drivers\etc\hosts or /etc/hosts) or other passive means (such as local Arp cache entries) in order to discover the presence of remote systems in an environment.
Adversaries may also target discovery of network infrastructure as well as leverage Network Device CLI commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).
used by actors
40 known groups
corpus indicators tagged T1018
910 carry this technique
A shared-technique signal for hunting: each row resolves to its own verdict. Not attribution to any one group.
software
53 malware & tools implement this
showing top 30 by severity of 910