MITRE ATT&CK technique
System Network Configuration Discovery detection rulesT1016
System Network Configuration Discovery (T1016) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 12 community-maintained Sigma detection rules in the library mapped to T1016 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, opencanary, cisco.
OpenCanary - SNMP OID Request
highDetects instances where an SNMP service on an OpenCanary node has had an OID request.
opencanary · application
Potential Pikabot Discovery Activity
highDetects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups. The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
windows · process_creation
Potential Recon Activity Via Nltest.EXE
mediumDetects nltest commands that can be used for information discovery
windows · process_creation
Suspicious Network Connection to IP Lookup Service APIs
mediumDetects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.
windows · network_connection
Cisco Discovery
lowFind information about network devices that is not stored in config files
cisco
Firewall Configuration Discovery Via Netsh.EXE
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet
lowDetects execution of "Get-NetFirewallRule" or "Show-NetFirewallRule" to enumerate the local firewall rules on a host.
windows · ps_module
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows · process_creation
Suspicious Network Command
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Userdomain Variable Enumeration
lowDetects suspicious enumeration of the domain the user is associated with.
windows · process_creation
System Network Discovery - Linux
informationalDetects enumeration of local network configuration
linux · process_creation
System Network Discovery - macOS
informationalDetects enumeration of local network configuration
macos · process_creation