Techniques › T1016 › T1016.001
T1016.001 Internet Connection Discovery
discovery — Windows, Linux, macOS, ESXi · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
0
Sigma rules tagged attack.t1016.001
0
KEV CVEs mapped here
<p>Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, <code>tracert</code>, and GET requests to websites, or performing initial speed testing to confirm bandwidth.</p><p>Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0357 Behavioral Detection of Internet Connection Discovery v1.0
AN1015 WindowsExecution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains.Tunable:
DestinationIPTimeWindowUserContextAN1016 LinuxExecution of ping, traceroute, or curl/wget against public IPs/domains to verify Internet reachability.Tunable:DomainPatternsProtocolTypeAN1017 macOSExecution of ping, traceroute, or network utility tools to external destinations; may includescutilor system_profiler.Tunable:ExecutionFrequencyEnrichmentLevelAN1018 ESXiExecution ofping,vmkping, orcurlfrom shell or through automation jobs/scripts to verify Internet egress.Tunable:SSHSessionOriginTargetIP
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1016.001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1016) 12
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
· 2021-12-07 (modified 2025-10-18) · logsource: product=windows category=process_creation · 0e4164da-94bc-450d-a7be-a4b176179f1f
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
Author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
· 2023-02-09 (modified 2024-08-01) · logsource: product=windows category=process_creation · 43311e65-84d8-42a5-b3d4-c94d9b67038f
Detects suspicious enumeration of the domain the user is associated with.
Author: remotephone, oscd.community
· 2020-10-06 (modified 2024-08-29) · logsource: product=macos category=process_creation · 58800443-f9fc-4d55-ae0c-98a3966dfb97
Detects enumeration of local network configuration
Author: Craig Young, oscd.community, Georg Lauenstein
· 2021-07-24 (modified 2023-12-15) · logsource: product=windows category=process_creation · 5cc90652-4cbd-4241-aa3b-4b462fa5a248
Detects nltest commands that can be used for information discovery
Author: Andreas Braathen (mnemonic.io)
· 2023-10-27 (modified 2024-01-26) · logsource: product=windows category=process_creation · 698d4431-514f-4c82-af4d-cf573872a9f5
Detects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups.
The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
Author: Arun Chauhan
· 2023-02-03 · logsource: product=windows category=process_creation · 903076ff-f442-475a-b667-4f246bcc203b
Detects nltest commands that can be used for information discovery
Author: Austin Clark
· 2019-08-12 (modified 2023-01-04) · logsource: product=cisco service=aaa · 9705a6a1-6db6-4a16-a987-15b7151e299b
Find information about network devices that is not stored in config files
Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
· 2021-12-07 (modified 2025-10-19) · logsource: product=windows category=process_creation · a29c1813-ab1f-4dde-b489-330b952e91ae
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
Author: Ömer Günal and remotephone, oscd.community
· 2020-10-06 (modified 2022-09-15) · logsource: product=linux category=process_creation · e7bd1cfa-b446-4c88-8afb-403bcd79e3fa
Detects enumeration of local network configuration
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · e9856028-fd4e-46e6-b3d1-10f7ceb95078
Detects instances where an SNMP service on an OpenCanary node has had an OID request.
Author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
· 2023-07-13 · logsource: product=windows category=ps_module · ea207a23-b441-4a17-9f76-ad5be47d51d3
Detects execution of "Get-NetFirewallRule" or "Show-NetFirewallRule" to enumerate the local firewall rules on a host.
Author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems)
· 2023-04-24 (modified 2024-03-22) · logsource: product=windows category=network_connection · edf3485d-dac4-4d50-90e4-b0e5813f7e60
Detects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.