Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
GroupThreat Group-3390 | Threat Group-3390 has registered domains for C2. |
| T1588.002 Tool |
GroupThreat Group-3390 | Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor. |
| T1588.003 Code Signing Certificates |
GroupThreat Group-3390 | Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations. |
| T1608.001 Upload Malware |
GroupThreat Group-3390 | Threat Group-3390 has hosted malicious payloads on Dropbox. |
| T1608.002 Upload Tool |
GroupThreat Group-3390 | Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites. |
| T1608.004 Drive-by Target |
GroupThreat Group-3390 | Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest. |
| T1685.001 Disable or Modify Windows Event Log |
GroupThreat Group-3390 | Threat Group-3390 has used appcmd.exe to disable logging on a victim server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.