ipconfig
MITRE ATT&CK: S0100 View on attack.mitre.org
Aliases: ipconfig
- Profile updated
- 2026-07-07 15:32:08
Context
ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration.
Detection coverage
- 9 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
Used by threat actors
- FunnyDream (campaign)
- Magic Hound (threat-actor)
- Volt Typhoon (threat-actor)
- Orangeworm (threat-actor)
- GALLIUM (threat-actor)
- OilRig (threat-actor)
- APT32 (threat-actor)
- Ke3chang (threat-actor)
- HEXANE (threat-actor)
- APT29 (threat-actor)
- admin@338 (threat-actor)
- APT41 (threat-actor)
- APT1 (threat-actor)
- MirrorFace (threat-actor)
- Threat Group-3390 (threat-actor)
Reports & references
- MITRE ATT&CK — S0100 (report)
- Microsoft — Bb490921 (report)