BIOC
Informational
✕
Interface enumeration using netsh
Attackers may enumerate existing network interfaces using netsh.exe.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: System Network Configuration Discovery (T1016)
Indicator:
Process action type = execution AND target process cmd = *netsh* interface* show*
Preventable: yes