Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1018
MITRE ATT&CK Technique

T1018: Remote System Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as [Ping](https://attack.mitre.org/software/S0097), <code>net view</code> using [Net](https://attack.mitre.org/software/S0039), or, on ESXi servers, `esxcli network diag ping`. Adversaries may also analyze data from local host files (ex: <code>C:\Windows\System32\Drivers\etc\hosts</code> or <code>/etc/hosts</code>) or other passive means (such as local [Arp](https://attack.mitre.org/software/S0099) cache entries) in order to discover the presence of remote systems in an environment. Adversaries may also target discovery of network infrastructure as well as leverage [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands on network devices to gather detailed information about systems within a network (e.g. <code>show cdp neighbors</code>, <code>show arp</code>).(Citation: US-CERT-TA18-106A)(Citation: CISA AR21-126A FIVEHANDS May 2021)

Tactics
Discovery
Platforms
ESXi, Linux, macOS, Network Devices, Windows

▪Used by groups (40)

G0004Ke3changG0009Deep PandaG0010TurlaG0019NaikonG0022APT3G0027Threat Group-3390G0030Lotus BlossomG0034Sandworm TeamG0035DragonflyG0037FIN6G0045menuPassG0050APT32G0053FIN5G0059Magic HoundG0060BRONZE BUTLERG0061FIN8G0077LeafminerG0087APT39G0091SilenceG0093GALLIUMG0096APT41G0102Wizard SpiderG0106RockeG0114ChimeraG0117Fox KittenG0119Indrik SpiderG0125HAFNIUMG0129Mustang PandaG1001HEXANEG1003Ember BearG1006Earth LuscaG1015Scattered SpiderG1017Volt TyphoonG1022ToddyCatG1024AkiraG1030AgriusG1040PlayG1043BlackByteG1051Medusa GroupG1054MirrorFace

▪Software using this technique (53)

S0018SykipotmalwareS0039NettoolS0063SHOTPUTmalwareS0091EpicmalwareS0093Backdoor.OldreamalwareS0097PingtoolS0099ArptoolS0125RemsecmalwareS0140ShamoonmalwareS0154Cobalt StrikemalwareS0165OSInfomalwareS0233MURKYTOPmalwareS0236KwampirsmalwareS0241RATANKBAmalwareS0244ComniemalwareS0248ytymalwareS0266TrickBotmalwareS0335CarbonmalwareS0359NltesttoolS0365Olympic DestroyermalwareS0366WannaCrymalwareS0385njRATmalwareS0428PoetRATmalwareS0452USBferrymalwareS0488CrackMapExectoolS0521BloodHoundtoolS0534BazarmalwareS0552AdFindtoolS0570BitPaymermalwareS0575ContimalwareS0586TAINTEDSCRIBEmalwareS0590NBTscantoolS0599KinsingmalwareS0604IndustroyermalwareS0646SpicyOmelettemalwareS0650QakBotmalwareS0659DiavolmalwareS0684ROADToolstoolS0692SILENTTRINITYtoolS0694DRATzarusmalwareS0696FlagpromalwareS0698HermeticWizardmalwareS1044FunnyDreammalwareS1068BlackCatmalwareS1070Black BastamalwareS1081BADHATCHmalwareS1146MgBotmalwareS1159DUSTTRAPmalwareS1198GomirmalwareS1212RansomHubmalwareS1229HavocmalwareS1242QilinmalwareS9020LODEINFOmalware

▪Reference

T1018on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.