Adversaries may perform network connection enumeration to discover information about device communication patterns. If an adversary can inspect the state of a network connection with tools, such as Netstat(Citation: Netstat), in conjunction with [System Firmware](https://attack.mitre.org/techniques/T0857), then they can determine the role of certain devices on the network (Citation: MITRE). The adversary can also use [Network Sniffing](https://attack.mitre.org/techniques/T0842) to watch network traffic for details about the source, destination, protocol, and content.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Workstation
is related to Virtual Private Network (VPN) Server
is related to Jump Host
is related to Switch
is related to Human-Machine Interface (HMI)
is related to Firewall
is related to Data Gateway
is related to Distributed Control System (DCS) Controller
is related to Safety Controller
is related to Intelligent Electronic Device (IED)
is related to Programmable Logic Controller (PLC)
is related to Data Historian
is related to Control Server
is related to Application Server
is related to Remote Terminal Unit (RTU)
is related to Programmable Automation Controller (PAC)
is blocked by Detection of Network Connection Enumeration
is blocked by Mitigation Limited or Not Effective
Impressum German English