Test your SOC · about a minute

Can your SOC see someone drawing the map?

One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.

technique T1016 · System Network Configuration Discoveryseen in Lazarus Groupwhere any Windows box

What this is about

Can your SOC see an attacker reading your network layout?

Three commands tell an intruder where they are standing. ipconfig /all gives the addressing and the DNS servers, arp -a gives the neighbours this machine has recently spoken to, and route print gives what is reachable from here. Together they are the map, and they take about four seconds to draw.

The detection watches for those specific lookups running. None of them is rare on its own, which is why the useful signal is the cluster: several of them, from one process, inside a minute.

The detection watches one thing: the classic network-configuration lookups running — the addressing, the neighbours and the routes.

This is not hypothetical

The Lazarus Group is documented running system network configuration discovery on the machines it compromises. The map is what turns a single foothold into a plan — it says which segment this box is on, which resolver it trusts, and what else is worth reaching for.

No malware, no exploit, no admin rights: three commands that ship with Windows. The same three you are about to run.

The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.

The map comes first

An intruder cannot move until they know where they are. These three lookups answer that, and they answer it quietly.

Individually boring, together loud

One ipconfig is nothing. Three discovery commands from the same process inside a minute is a person working — and that is the pattern to alert on.

Nothing is written

All three are read-only and leave no file behind. If the command line was not logged, the step effectively did not happen as far as your evidence is concerned.

The test

Run the real thing. Safely. On a box you own.

Run the same three lookups an intruder runs, then open your alerts.

01

Read the addressing

Run ipconfig /all — the full network configuration, including the DNS servers this machine trusts.

02

Read the neighbours and the routes

Run arp -a and then route print. This is the moment your SOC should see a cluster of discovery, not a single lookup.

03

Check your alerts

Open your SOC or EDR. Did network configuration discovery fire — or did the map get drawn in silence?

test-your-soc-network-config.ps1 · PowerShell · a machine you own
# test-your-soc-network-config.ps1 — run on a machine you own.
# Safe: three read-only lookups of this machine's own network settings. Nothing to undo.
# STEP 1 - the full network configuration, the way an intruder reads it.
ipconfig /all
# STEP 2 - the neighbours this machine has recently spoken to.
arp -a
# STEP 3 - the routing table, which shows what else is reachable from here.
route print
# STEP 4 - open your SOC / EDR. Did network configuration discovery alert?

All three lines only print settings this machine already holds. Nothing is created, changed or deleted, so there is nothing to undo and no admin rights are needed.

Reading the result — honestly

Something fired

Your tooling watches the network-configuration lookups

Good — you would see an intruder drawing the map in the minutes before they used it. On to the next one.

Silence

The map got drawn unseen — now you know

Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below closes it.

Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged one of the discovery commands — note that a single lookup is often a genuine help-desk call, so the catch worth tuning for is several of them together, or one launched by a parent that has no business asking. Treat a pass as a reason to go check prod, not a finish line.

How to catch it

Missed it? Here’s the fix — take it straight to your SOC.

The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.

proc_creation_win_susp_network_command.yml
title: Suspicious Network Command
id: a29c1813-ab1f-4dde-b489-330b952e91ae
status: test
description: Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1016/T1016.md#atomic-test-1---system-network-configuration-discovery-on-windows
author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
date: 2021-12-07
modified: 2025-10-19
tags:
    - attack.discovery
    - attack.t1016
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|re:
            - 'ipconfig\s+/all'
            - 'netsh\s+interface show interface'
            - 'arp\s+-a'
            - 'nbtstat\s+-n'
            - 'net\s+config'
            - 'route\s+print'
    condition: selection
falsepositives:
    - Administrator, hotline ask to user
level: low

Suspicious Network Command · SigmaHQ rule a29c1813-ab1f-4dde-b489-330b952e91ae

Author frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_network_command.yml

Retrieved 2026-09-11 · file sha256 ea9b3d15a8419787940b14991faf715c0dd05628c311e18ac9d1558e7fbe120d

If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.

A new one every week

This is technique 08 of many.

Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.

Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →

Credit & sources

The technique and the incident are documented by MITRE ATT&CK (T1016) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.

CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI