kevmap

TechniquesT1016 › T1016.002

T1016.002 Wi-Fi Discovery

discovery — Linux, Windows, macOS · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
0
Sigma rules tagged attack.t1016.002
0
KEV CVEs mapped here
<p>Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Account Discovery, Remote System Discovery, and other discovery or Credential Access activity to support both ongoing and future campaigns.</p><p>Adversaries may collect various types of information about Wi-Fi networks from hosts. For example, on Windows names and passwords of all Wi-Fi networks a device has previously connected to may be available through netsh wlan show profiles to enumerate Wi-Fi names and then netsh wlan show profile “Wi-Fi name” key=clear to show a Wi-Fi network’s corresponding password. Additionally, names and other details of locally reachable Wi-Fi networks can be discovered using calls to wlanAPI.dll Native API functions.</p><p>On Linux, names and passwords of all Wi-Fi-networks a device has previously connected to may be available in files under /etc/NetworkManager/system-connections/. On macOS, the password of a known Wi-Fi may be identified with security find-generic-password -wa wifiname (requires admin username/password).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1016.002

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1016) 12

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io' · 2021-12-07 (modified 2025-10-18) · logsource: product=windows category=process_creation · 0e4164da-94bc-450d-a7be-a4b176179f1f
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
Techniques: T1016
Author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io · 2023-02-09 (modified 2024-08-01) · logsource: product=windows category=process_creation · 43311e65-84d8-42a5-b3d4-c94d9b67038f
Detects suspicious enumeration of the domain the user is associated with.
Techniques: T1016
Author: remotephone, oscd.community · 2020-10-06 (modified 2024-08-29) · logsource: product=macos category=process_creation · 58800443-f9fc-4d55-ae0c-98a3966dfb97
Detects enumeration of local network configuration
Techniques: T1016
Author: Craig Young, oscd.community, Georg Lauenstein · 2021-07-24 (modified 2023-12-15) · logsource: product=windows category=process_creation · 5cc90652-4cbd-4241-aa3b-4b462fa5a248
Detects nltest commands that can be used for information discovery
Techniques: T1016T1482
Author: Andreas Braathen (mnemonic.io) · 2023-10-27 (modified 2024-01-26) · logsource: product=windows category=process_creation · 698d4431-514f-4c82-af4d-cf573872a9f5
Detects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups. The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
Techniques: T1016T1049T1087
Author: Arun Chauhan · 2023-02-03 · logsource: product=windows category=process_creation · 903076ff-f442-475a-b667-4f246bcc203b
Detects nltest commands that can be used for information discovery
Techniques: T1016T1018T1482
Author: Austin Clark · 2019-08-12 (modified 2023-01-04) · logsource: product=cisco service=aaa · 9705a6a1-6db6-4a16-a987-15b7151e299b
Find information about network devices that is not stored in config files
Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io' · 2021-12-07 (modified 2025-10-19) · logsource: product=windows category=process_creation · a29c1813-ab1f-4dde-b489-330b952e91ae
Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
Techniques: T1016
Author: Ömer Günal and remotephone, oscd.community · 2020-10-06 (modified 2022-09-15) · logsource: product=linux category=process_creation · e7bd1cfa-b446-4c88-8afb-403bcd79e3fa
Detects enumeration of local network configuration
Techniques: T1016
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · e9856028-fd4e-46e6-b3d1-10f7ceb95078
Detects instances where an SNMP service on an OpenCanary node has had an OID request.
Techniques: T1016T1021
Author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io · 2023-07-13 · logsource: product=windows category=ps_module · ea207a23-b441-4a17-9f76-ad5be47d51d3
Detects execution of "Get-NetFirewallRule" or "Show-NetFirewallRule" to enumerate the local firewall rules on a host.
Techniques: T1518.001T1016
Author: Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems) · 2023-04-24 (modified 2024-03-22) · logsource: product=windows category=network_connection · edf3485d-dac4-4d50-90e4-b0e5813f7e60
Detects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.
Techniques: T1016