T1016.001 Internet Connection Discovery
Sub-technique of T1016 System Network Configuration Discovery
Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using [Ping](https://attack.mitre.org/software/S0097), tracert, and GET requests to websites, or performing initial speed testing to confirm bandwidth. Adversaries may use the results and responses from these requests to…
Who uses it · with stories on Jábega
Sigma rules to hunt it
SigmaHQ has no rules for this technique.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.