Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1049
MITRE ATT&CK Technique

T1049: System Network Connections Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An adversary who gains access to a system that is part of a cloud-based environment may map out Virtual Private Clouds or Virtual Networks in order to determine what systems and services are connected. The actions performed are likely the same types of discovery techniques depending on the operating system, but the resulting information may include details about the networked cloud environment relevant to the adversary's goals. Cloud providers may have different ways in which their virtual networks operate.(Citation: Amazon AWS VPC Guide)(Citation: Microsoft Azure Virtual Network Overview)(Citation: Google VPC Overview) Similarly, adversaries who gain access to network devices may also perform similar discovery activities to gather information about connected systems and services. Utilities and commands that acquire this information include [netstat](https://attack.mitre.org/software/S0104), "net use," and "net session" with [Net](https://attack.mitre.org/software/S0039). In Mac and Linux, [netstat](https://attack.mitre.org/software/S0104) and <code>lsof</code> can be used to list current connections. <code>who -a</code> and <code>w</code> can be used to show which users are currently logged in, similar to "net session". Additionally, built-in features native to network devices and [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) may be used (e.g. <code>show ip sockets</code>, <code>show tcp brief</code>).(Citation: US-CERT-TA18-106A) On ESXi servers, the command `esxi network ip connection list` can be used to list active network connections.(Citation: Sygnia ESXi Ransomware 2025)

Tactics
Discovery
Platforms
ESXi, IaaS, Linux, macOS, Network Devices, Windows

▪Used by groups (32)

G0004Ke3changG0006APT1G0010TurlaG0018admin@338G0022APT3G0027Threat Group-3390G0030Lotus BlossomG0032Lazarus GroupG0033Poseidon GroupG0034Sandworm TeamG0045menuPassG0049OilRigG0050APT32G0059Magic HoundG0069MuddyWaterG0081Tropic TrooperG0082APT38G0093GALLIUMG0096APT41G0114ChimeraG0129Mustang PandaG0135BackdoorDiplomacyG0138AndarielG0139TeamTNTG1001HEXANEG1006Earth LuscaG1016FIN13G1017Volt TyphoonG1022ToddyCatG1023APT5G1032INC RansomG1047Velvet Ant

▪Software using this technique (60)

S0013PlugXmalwareS0018SykipotmalwareS0038DuqumalwareS0039NettoolS0063SHOTPUTmalwareS0089BlackEnergymalwareS0091EpicmalwareS0094Trojan.KaraganymalwareS0102nbtstattoolS0104netstattoolS0125RemsecmalwareS0153RedLeavesmalwareS0154Cobalt StrikemalwareS0165OSInfomalwareS0180VolgmermalwareS0184POWRUNERmalwareS0192PupytoolS0198NETWIREmalwareS0236KwampirsmalwareS0237GravityRATmalwareS0241RATANKBAmalwareS0244ComniemalwareS0251ZebrocymalwareS0283jRATmalwareS0335CarbonmalwareS0356KONNImalwareS0363EmpiretoolS0374SpeakUpmalwareS0378PoshC2toolS0439OkrummalwareS0443MESSAGETAPmalwareS0445ShimRatReportertoolS0449MazemalwareS0452USBferrymalwareS0456Aria-bodymalwareS0458RamsaymalwareS0488CrackMapExectoolS0532LucifermalwareS0533SLOTHFULMEDIAmalwareS0554EgregormalwareS0567DtrackmalwareS0575ContimalwareS0579WaterbearmalwareS0589SibotmalwareS0625CubamalwareS0633SlivertoolS0638BabukmalwareS0650QakBotmalwareS0678TorismamalwareS0681LizarmalwareS0696FlagpromalwareS1032PyDCryptmalwareS1060MafaldamalwareS1075KOPILUWAKmalwareS1081BADHATCHmalwareS1085SardonicmalwareS1091PacutoolS1141LunarWebmalwareS1144FRPtoolS1228PUBLOADmalware

▪Reference

T1049on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.