Arp

MITRE ATT&CK: S0099 View on attack.mitre.org

Aliases: arp.exe, Arp

Operating systems
linux, windows, macos
Profile updated
2026-07-07 15:32:44

Context

Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache.

Detection coverage

  • 25 Sigma rules

Malware & tools used

  • Remote System Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Used by threat actors

  • 2025 Poland Wiper Attacks (campaign)
  • Operation AkaiRyū (campaign)
  • C0026 (campaign)
  • Turla (threat-actor)
  • APT32 (threat-actor)
  • Orangeworm (threat-actor)
  • BlackByte (threat-actor)

Reports & references

  • MITRE ATT&CK — S0099 (report)
  • Microsoft — Bb490864 (report)

External references