32
Groups Using This
1
Tactics
6
Platforms
33
Prevalence Rank
Description

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of discovery techniques depending on the operating system, but the resulting information may include details about the networked cloud environment relevant to the adversary's goals. Cloud providers may have different ways in which their virtual networks operate. Similarly, adversaries who gain access to network devices may also perform similar discovery activities to gather information about connected systems and services. Utilities and commands that acquire this information include netstat, "net use," and "net session" with Net. In Mac and Linux, netstat and lsof can be used to list current connections. who -a and w can be used to show which users are currently logged in, similar to "net session". Additionally, built-in features native to network devices and Network Device CLI may be used (e.g. show ip sockets, show tcp brief). On ESXi servers, the command `esxi network ip connection list` can be used to list active network connections.

View MITRE record โ†—

Platforms
ESXiIaaSLinuxmacOSNetwork DevicesWindows
Groups Using T1049 (32)
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0010
Turla
๐Ÿ‡ท๐Ÿ‡บ Russia68 techniques30 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0139
TeamTNT
56 techniques4 software
G1016
FIN13
53 techniques4 software
G0045
menuPass
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques25 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0081
Tropic Trooper
40 techniques6 software
G1001
HEXANE
36 techniques12 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G1022
ToddyCat
25 techniques9 software
G1032
INC Ransom
25 techniques8 software
G0006
APT1
๐Ÿ‡จ๐Ÿ‡ณ China23 techniques17 software
G1047
Velvet Ant
22 techniques2 software
G0030
Lotus Blossom
21 techniques9 software
G0135
BackdoorDiplomacy
15 techniques5 software
G0138
Andariel
๐Ÿ‡ฐ๐Ÿ‡ต North Korea12 techniques2 software
G0018
admin@338
๐Ÿ‡จ๐Ÿ‡ณ China12 techniques7 software
G0033
Poseidon Group
8 techniques0 software
โ†‘