{"id":"T1016","name":"System Network Configuration Discovery","url":"https://attack.mitre.org/techniques/T1016","tactics":["discovery"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0195","stix_id":"x-mitre-detection-strategy--172cff54-a89b-4207-abc2-8d0c9601025e","name":"Behavioral Detection of System Network Configuration Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0195","analytics":[{"id":"AN0559","stix_id":"x-mitre-analytic--edfec58e-e591-4057-a906-1baf3674d80b","name":"Analytic 0559","description":"Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.","url":"https://attack.mitre.org/detectionstrategies/DET0195#AN0559","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"ParentProcess","description":"Filter known/legit CLI chains (e.g., explorer.exe → cmd.exe) to reduce FP"},{"field":"UserContext","description":"Target executions by non-admin or unexpected users"},{"field":"TimeWindow","description":"Cluster enumeration commands within short time windows"}],"live":true,"detection_strategies":["DET0195"],"techniques":["T1016"]},{"id":"AN0560","stix_id":"x-mitre-analytic--6a57daad-9d2c-4851-a46e-b6ebac607a4c","name":"Analytic 0560","description":"Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration.","url":"https://attack.mitre.org/detectionstrategies/DET0195#AN0560","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Match regex for variations in enumeration syntax (e.g., `ip -4 addr show`)"},{"field":"InteractiveShellIndicator","description":"Differentiate scripted versus interactive sessions"}],"live":true,"detection_strategies":["DET0195"],"techniques":["T1016"]},{"id":"AN0561","stix_id":"x-mitre-analytic--79c196d7-abb8-4766-a875-4acafc6f059d","name":"Analytic 0561","description":"Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status.","url":"https://attack.mitre.org/detectionstrategies/DET0195#AN0561","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ScriptedContext","description":"Scripted tools (e.g., bash calling `ifconfig`) vs GUI-initiated inspection"},{"field":"ExecutionFrequency","description":"Enumerations executed frequently or across multiple interfaces may indicate enumeration loops"}],"live":true,"detection_strategies":["DET0195"],"techniques":["T1016"]},{"id":"AN0562","stix_id":"x-mitre-analytic--cb70ad2f-7c96-4669-baed-3007246b0630","name":"Analytic 0562","description":"Use of `esxcli network` commands (e.g., `esxcli network nic list`, `esxcli network ip interface ipv4 get`) via SSH or hostd to enumerate adapter and IP information.","url":"https://attack.mitre.org/detectionstrategies/DET0195#AN0562","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"SSHSessionOrigin","description":"Detection may vary based on internal vs remote terminal usage"},{"field":"esxcliCommandDepth","description":"Distinguish between benign status checks and deep enumeration chains"}],"live":true,"detection_strategies":["DET0195"],"techniques":["T1016"]},{"id":"AN0563","stix_id":"x-mitre-analytic--e7debe02-4326-48ae-aa22-59c2a847d3e7","name":"Analytic 0563","description":"CLI-based execution of interface and routing discovery commands (e.g., `show ip interface`, `show arp`, `show route`) over Telnet, SSH, or console.","url":"https://attack.mitre.org/detectionstrategies/DET0195#AN0563","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"Username","description":"Highlight low-privileged or non-routine users performing discovery"},{"field":"CommandString","description":"Allow for tuning based on command regex or frequency"},{"field":"TransportType","description":"SSH vs Telnet vs Console session logging scope"}],"live":true,"detection_strategies":["DET0195"],"techniques":["T1016"]}],"live":true,"version":"1.0","techniques":["T1016"]}],"sigma_rules":[{"id":"0e4164da-94bc-450d-a7be-a4b176179f1f","title":"Firewall Configuration Discovery Via Netsh.EXE","author":"frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'","status":"test","level":"low","date":"2021-12-07","modified":"2025-10-18","description":"Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1016/T1016.md#atomic-test-2---list-windows-firewall-rules","https://ss64.com/nt/netsh.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016"],"path":"rules/windows/process_creation/proc_creation_win_netsh_fw_rules_discovery.yml","techniques":["T1016"],"cves":[]},{"id":"43311e65-84d8-42a5-b3d4-c94d9b67038f","title":"Userdomain Variable Enumeration","author":"Christopher Peacock @SecurePeacock, SCYTHE @scythe_io","status":"test","level":"low","date":"2023-02-09","modified":"2024-08-01","description":"Detects suspicious enumeration of the domain the user is associated with.","references":["https://www.arxiv-vanity.com/papers/2008.04676/","https://thedfirreport.com/2022/11/14/bumblebee-zeros-in-on-meterpreter/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016"],"path":"rules-placeholder/windows/process_creation/proc_creation_win_userdomain_variable_enumeration.yml","techniques":["T1016"],"cves":[]},{"id":"58800443-f9fc-4d55-ae0c-98a3966dfb97","title":"System Network Discovery - macOS","author":"remotephone, oscd.community","status":"test","level":"informational","date":"2020-10-06","modified":"2024-08-29","description":"Detects enumeration of local network configuration","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1016/T1016.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.discovery","attack.t1016"],"path":"rules/macos/process_creation/proc_creation_macos_susp_system_network_discovery.yml","techniques":["T1016"],"cves":[]},{"id":"5cc90652-4cbd-4241-aa3b-4b462fa5a248","title":"Potential Recon Activity Via Nltest.EXE","author":"Craig Young, oscd.community, Georg Lauenstein","status":"test","level":"medium","date":"2021-07-24","modified":"2023-12-15","description":"Detects nltest commands that can be used for information discovery","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731935(v=ws.11)","https://thedfirreport.com/2021/08/16/trickbot-leads-up-to-fake-1password-installation/","https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/","https://book.hacktricks.xyz/windows/basic-cmd-for-pentesters","https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/","https://eqllib.readthedocs.io/en/latest/analytics/03e231a6-74bc-467a-acb1-e5676b0fb55e.html","https://redcanary.com/blog/how-one-hospital-thwarted-a-ryuk-ransomware-outbreak/","https://github.com/redcanaryco/atomic-red-team/blob/5360c9d9ffa3b25f6495f7a16e267b719eba2c37/atomics/T1482/T1482.md#atomic-test-2---windows---discover-domain-trusts-with-nltest"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_nltest_recon.yml","techniques":["T1016","T1482"],"cves":[]},{"id":"698d4431-514f-4c82-af4d-cf573872a9f5","title":"Potential Pikabot Discovery Activity","author":"Andreas Braathen (mnemonic.io)","status":"test","level":"high","date":"2023-10-27","modified":"2024-01-26","description":"Detects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups.\nThe malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).\n","references":["https://www.virustotal.com/gui/file/72f1a5476a845ea02344c9b7edecfe399f64b52409229edaf856fcb9535e3242","https://tria.ge/231023-lpw85she57/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1049","attack.t1087","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Pikabot/proc_creation_win_malware_pikabot_discovery.yml","techniques":["T1016","T1049","T1087"],"cves":[]},{"id":"903076ff-f442-475a-b667-4f246bcc203b","title":"Nltest.EXE Execution","author":"Arun Chauhan","status":"test","level":"low","date":"2023-02-03","modified":null,"description":"Detects nltest commands that can be used for information discovery","references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/nltest.htm"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016","attack.t1018","attack.t1482"],"path":"rules/windows/process_creation/proc_creation_win_nltest_execution.yml","techniques":["T1016","T1018","T1482"],"cves":[]},{"id":"9705a6a1-6db6-4a16-a987-15b7151e299b","title":"Cisco Discovery","author":"Austin Clark","status":"test","level":"low","date":"2019-08-12","modified":"2023-01-04","description":"Find information about network devices that is not stored in config files","references":["https://www.cisco.com/c/en/us/td/docs/server_nw_virtual/2-5_release/command_reference/show.html"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.discovery","attack.t1083","attack.t1201","attack.t1057","attack.t1018","attack.t1082","attack.t1016","attack.t1049","attack.t1033","attack.t1124"],"path":"rules/network/cisco/aaa/cisco_cli_discovery.yml","techniques":["T1083","T1201","T1057","T1018","T1082","T1016","T1049","T1033","T1124"],"cves":[]},{"id":"a29c1813-ab1f-4dde-b489-330b952e91ae","title":"Suspicious Network Command","author":"frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'","status":"test","level":"low","date":"2021-12-07","modified":"2025-10-19","description":"Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1016/T1016.md#atomic-test-1---system-network-configuration-discovery-on-windows"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1016"],"path":"rules/windows/process_creation/proc_creation_win_susp_network_command.yml","techniques":["T1016"],"cves":[]},{"id":"e7bd1cfa-b446-4c88-8afb-403bcd79e3fa","title":"System Network Discovery - Linux","author":"Ömer Günal and remotephone, oscd.community","status":"test","level":"informational","date":"2020-10-06","modified":"2022-09-15","description":"Detects enumeration of local network configuration","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1016/T1016.md"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.discovery","attack.t1016"],"path":"rules/linux/process_creation/proc_creation_lnx_system_network_discovery.yml","techniques":["T1016"],"cves":[]},{"id":"e9856028-fd4e-46e6-b3d1-10f7ceb95078","title":"OpenCanary - SNMP OID Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SNMP service on an OpenCanary node has had an OID request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.discovery","attack.lateral-movement","attack.t1016","attack.t1021"],"path":"rules/application/opencanary/opencanary_snmp_cmd.yml","techniques":["T1016","T1021"],"cves":[]},{"id":"ea207a23-b441-4a17-9f76-ad5be47d51d3","title":"Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet","author":"Christopher Peacock @SecurePeacock, SCYTHE @scythe_io","status":"test","level":"low","date":"2023-07-13","modified":null,"description":"Detects execution of \"Get-NetFirewallRule\" or \"Show-NetFirewallRule\" to enumerate the local firewall rules on a host.","references":["https://learn.microsoft.com/en-us/powershell/module/netsecurity/get-netfirewallrule?view=windowsserver2022-ps","https://learn.microsoft.com/en-us/powershell/module/netsecurity/show-netfirewallrule?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_module"},"tags":["detection.threat-hunting","attack.discovery","attack.t1518.001","attack.t1016"],"path":"rules-threat-hunting/windows/powershell/powershell_module/posh_pm_susp_netfirewallrule_recon.yml","techniques":["T1518.001","T1016"],"cves":[]},{"id":"edf3485d-dac4-4d50-90e4-b0e5813f7e60","title":"Suspicious Network Connection to IP Lookup Service APIs","author":"Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-04-24","modified":"2024-03-22","description":"Detects external IP address lookups by non-browser processes via services such as \"api.ipify.org\". This could be indicative of potential post compromise internet test activity.","references":["https://github.com/rsp/scripts/blob/c8bb272d68164a9836e4f273d8f924927f39b8c6/externalip-benchmark.md","https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a","https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/","https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.discovery","attack.t1016"],"path":"rules/windows/network_connection/net_connection_win_domain_external_ip_lookup.yml","techniques":["T1016"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-40449","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}