BIOC Informational

Interface enumeration using netsh

Attackers may enumerate existing network interfaces using netsh.exe.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: System Network Configuration Discovery (T1016)
Indicator:

Process action type = execution AND target process cmd = *netsh* interface* show*

Preventable: yes