Conti can retrieve the ARP cache from the local system by using the GetIpNetTable() API call and check to ensure IP addresses it connects to are for local, non-Internet, systems.4
tool
Conti S0575
- Type
- malware
- Platform
- Windows
- Created
- 17 February 2021
- Last modified
- 16 April 2025
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0575
Conti has the ability to discover hosts on a target network.5
Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.67
Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.8910
Conti can enumerate routine network connections from a compromised host.11
Conti has loaded an encrypted DLL into memory and then executes it.1213
Standing S0575
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
70th percentile · 70% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
53rd percentile · 53% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
64th percentile · 64% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S0575
494 distinct rules cover the 16 techniques recorded for this tool. The 522 technique-to-rule mappings resolve to 494 distinct rules, because one rule can cover several techniques. 356 Sigma · 138 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org