44
Groups Using This
1
Tactics
5
Platforms
22
Prevalence Rank
Description

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. Adversaries may also leverage a Network Device CLI on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. show ip route, show ip interface). On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address. Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.

View MITRE record โ†—

Platforms
ESXiLinuxmacOSNetwork DevicesWindows
Groups Using T1016 (44)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0010
Turla
๐Ÿ‡ท๐Ÿ‡บ Russia68 techniques30 software
G1015
Scattered Spider
64 techniques9 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0139
TeamTNT
56 techniques4 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G1016
FIN13
53 techniques4 software
G1043
BlackByte
48 techniques8 software
G1057
ShinyHunters
46 techniques1 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0125
HAFNIUM
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G0081
Tropic Trooper
40 techniques6 software
G1001
HEXANE
36 techniques12 software
G1044
APT42
๐Ÿ‡ฎ๐Ÿ‡ท Iran32 techniques2 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G0121
Sidewinder
๐Ÿ‡จ๐Ÿ‡ณ China30 techniques1 software
G0128
ZIRCONIUM
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques0 software
G0126
Higaisa
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1040
Play
26 techniques9 software
G0012
Darkhotel
๐Ÿ‡ฐ๐Ÿ‡ท South Korea24 techniques0 software
G0006
APT1
๐Ÿ‡จ๐Ÿ‡ณ China23 techniques17 software
G0030
Lotus Blossom
21 techniques9 software
G0073
APT19
๐Ÿ‡จ๐Ÿ‡ณ China21 techniques2 software
G1008
SideCopy
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan16 techniques2 software
G0038
Stealth Falcon
16 techniques0 software
G0019
Naikon
๐Ÿ‡จ๐Ÿ‡ณ China14 techniques15 software
G0018
admin@338
๐Ÿ‡จ๐Ÿ‡ณ China12 techniques7 software
G1009
Moses Staff
๐Ÿ‡ฎ๐Ÿ‡ท Iran12 techniques4 software
โ†‘