System Network Connections Discovery T1049
Tactic: Discovery
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Events covered
14 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 3 | Network connection |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Security-Auditing | Event ID 5156 | The Windows Filtering Platform has permitted a connection. |
| ESF | exec | Process Execution |
| Linux-Auditd | Event ID 1101 | USER_ACCT |
| Linux-Auditd | Event ID 1103 | CRED_ACQ |
| Linux-Auditd | Event ID 1105 | USER_START |
| Linux-Auditd | Event ID 1106 | USER_END |
| Linux-Auditd | Event ID 1123 | USER_CMD |
| PowerShell | Event ID 4103 | Payload Context: ContextInfo User Data: UserData. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| PowerShell | Event ID 400 | Event ID 400 |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 36 rules share fields, values, and exclusions.
Fields filtered most (34 distinct)
These fields appear most often in rule filters.
Top indicator values (471 distinct)
These values appear most often in rule predicates.
Exclusions (132 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 9 rules
- Cisco Discovery
- HackTool - SharpView Execution
- Net.EXE Execution
- Potential Pikabot Discovery Activity
- System Network Connections Discovery - Linux
- System Network Connections Discovery - MacOs
- System Network Connections Discovery Via Net.EXE
- Use Get-NetTCPConnection
- Use Get-NetTCPConnection - PowerShell Module
Elastic 9 rules
- Deprecated - PowerShell Script with Discovery Capabilities
- DNS Enumeration Detected via Defend for Containers
- Enumeration Command Spawned via WMIPrvSE
- Suspicious JetBrains TeamCity Child Process
- Suspicious MS Office Child Process
- Suspicious System Commands Executed by Previously Unknown Executable
- System Network Connections Discovery
- Unusual Linux Network Connection Discovery
- Windows System Network Connections Discovery
Splunk 17 rules
- Common Recon Commands in Short Burst (Sysmon)
- Common Recon Commands in Short Burst (Windows Event Log)
- GetNetTcpconnection with PowerShell
- GetNetTcpconnection with PowerShell Script Block
- Linux Enumeration Techniques
- List Open Egress Ports (Sysmon)
- List Open Egress Ports (Windows Event Log)
- Network Connection Discovery With Arp
- Network Connection Discovery With Netstat
- PowerView_SharpView Commands (PowerShell)
- System Network Connections Discovery - Windows (PowerShell)
- System Network Connections Discovery - Windows (Sysmon)
- System Network Connections Discovery - Windows (Windows Event Log)
- Windows Common Abused Cmd Shell Risk Behavior
- Windows Network Connection Discovery Via Net
- Windows Post Exploitation Risk Behavior
- Windows System Network Connections Discovery Netsh