Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1016.001 — Internet Connection Discovery
T1016.001

Internet Connection Discovery

Discovery
TLP:CLEAR

Description

Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, <code>tracert</code>, and GET requests to websites, or performing initial speed testing to confirm bandwidth. Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.

MITRE ATT&CK Detection Strategies
1

DET0357 Behavioral Detection of Internet Connection Discovery
AN1016 Linux

Execution of ping, traceroute, or curl/wget against public IPs/domains to verify Internet reachability.

auditd:EXECVE linux:syslog
AN1017 macOS

Execution of ping, traceroute, or network utility tools to external destinations; may include `scutil` or system_profiler.

macos:unifiedlog
AN1018 ESXi

Execution of `ping`, `vmkping`, or `curl` from shell or through automation jobs/scripts to verify Internet egress.

esxi:shell esxi:hostd
+1 more analytics

Details

Platforms
Windows
Linux
Macos
Esxi
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.