MITRE ATT&CK technique
T1016 — System Network Configuration Discovery
Last fetched
T1016 (System Network Configuration Discovery) is a MITRE ATT&CK technique tracked in WhisperGraph, serving the Discovery tactic.
Description
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include [Arp](https://attack.mitre.org/software/S0099), [ipconfig](https://attack.mitre.org/software/S0100)/[ifconfig](https://attack.mitre.org/software/S0101), [nbtstat](https://attack.mitre.org/software/S0102), and [route](https://attack.mitre.org/software/S0103). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. <code>show ip route</code>, <code>show ip interface</code>).(Citation: US-CERT-TA18-106A)(Citation: Mandiant APT41 Global Intrusion ) On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address.(Citation: Trellix Rnasomhouse 2024) Adversaries may use the information from [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016) during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.
Tactics
Related techniques
Threat actors observed using this technique
- Dragonfly
- Naikon
- Volt Typhoon
- Mustang Panda
- Play
- Stealth Falcon
- Higaisa
- Earth Lusca
- APT3
- APT1
- Threat Group-3390
- Scattered Spider
- HEXANE
- MirrorFace
- Ke3chang
- Medusa Group
- menuPass
- FIN13
- BlackByte
- ZIRCONIUM
- Wizard Spider
- ShinyHunters
- SideCopy
- APT42
- APT41
- Moses Staff
- Turla
- MuddyWater
- APT32
- Lotus Blossom
- Magic Hound
- GALLIUM
- Kimsuky
- OilRig
- TeamTNT
- Tropic Trooper
- APT19
- Sidewinder
- admin@338
- Darkhotel
- Moonstone Sleet
- Chimera
- HAFNIUM
- Lazarus Group
- WIZARD SPIDER
- MUSTANG PANDA
- DarkHotel
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1016 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.