System Network Configuration Discovery T1016

Tactic: Discovery

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 74 rules share fields, values, and exclusions.

Fields filtered most (69 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name30eq 15, in 8, wildcard 4, is_not_null 2, regex_match 2, starts_with 2, contains 1arp.exe, atbroker.exe, bash, bginfo.exe, dsquery.exe
CommandLine21contains 14, regex_match 5, eq 2, is_not_null 1(?i)(objectcategory|trustdmp|member\s(.*)?-list), /library/preferences/com.apple.alf, a, read , (?i)(objectcategory|trustdmp|member.*?\s+\-list)
host.os.type21eq 18, in 3
event.type17eq 17start
Image16ends_with 9, starts_with 5, wildcard 5, eq 3, is_not_null 1/boot/, /dev/shm/, /ifconfig, \netsh.exe, \nltest.exe
EventType14eq 10, in 3, wildcard 1exec, start, exec_event, Process Create*, ProcessRollup2
EventID13eq 134688, 4104, 4103, 1
OriginalFileName10eq 10net.exe, net1.exe, netsh.exe, nltestrk.exe, adexp
process.args9eq 7, wildcard 3, in 2, starts_with 2, contains 1-s, (objectcategory=attributeschema), (objectcategory=computer), (objectcategory=group), *.cluster.local
parent_process_name7eq 3, in 3, starts_with 1bash, sh, zsh, ., acrobat.exe
ParentImage6ends_with 2, starts_with 2, eq 1, is_not_null 1./, /applications/, /bin/, /dev/shm/, /private/var/folders/
QueryName6wildcard 4, contains 1, eq 1, is_not_null 1api.2ip.ua, *.geojs.io, *portmap.io, *api.ipify.org, *checkip.amazonaws.com
event.category6eq 6process, network
ScriptBlockText5in 3, contains 2, eq 1*get-clipboardtext*, *returnhotfixid*, *start-aclcheck*, .getgporeport(), ::getipglobalproperties()
Type5eq 5

Top indicator values (1044 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
171078
EventIDeq
4688
6317
EventIDeq
4104
5269
process_nameeq
nbtstat.exe
69
process_nameeq
net.exe
628
process_nameeq
arp.exe
59
process_nameeq
cmstp.exe
525
process_nameeq
cscript.exe
567
process_nameeq
dsget.exe
58
process_nameeq
dsquery.exe
512
process_nameeq
installutil.exe
537
process_nameeq
ipconfig.exe
510
process_nameeq
mshta.exe
584
process_nameeq
msxsl.exe
523
process_nameeq
net1.exe
539
process_nameeq
netsh.exe
521
process_nameeq
netstat.exe
59
process_nameeq
nltest.exe
511
process_nameeq
powershell.exe
5184
process_nameeq
pwsh.exe
577
process_nameeq
regasm.exe
526
process_nameeq
regsvcs.exe
523
process_nameeq
regsvr32.exe
573
process_nameeq
wmic.exe
566
process_nameeq
wscript.exe
583
process_nameeq
xwizard.exe
516
process_nameeq
cmd.exe
4121
process_nameeq
gpresult.exe
47
event.categoryeq
process
5142
EventTypeeq
exec
4576

Exclusions (294 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
3
process_nameeq
powershell.exe
2
user.ideq
s-1-5-18
2
user.idin
S-1-5-19
2
CommandLineeq
c:\program files\powershell\7\pwsh.exe
1
CurrentDirectoryeq
/opt/outline-server
1
CurrentDirectoryin
/opt/SolarWinds/Agent/bin/Plugins/SCM
1
CurrentDirectoryin
/opt/cohesityagent/software/crux/bin
1
CurrentDirectoryin
/opt/microsoft/mdatp/sbin
1
CurrentDirectoryin
/usr/lib/check_mk_agent/plugins
1
CurrentDirectoryin
/var/ossec
1
CurrentDirectorywildcard
\\VMHOST\Users\*\Downloads\
1
Effective_process.executableeq
/applications/docker.app/contents/macos/docker
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 16 rules

Elastic 30 rules

Splunk 25 rules

Kusto 2 rules

YARA-L 1 rule