Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1595.002 Vulnerability Scanning |
GroupDragonfly | Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services. |
| T1598.002 Spearphishing Attachment |
GroupDragonfly | Dragonfly has used spearphishing with Microsoft Office attachments to enable harvesting of user credentials. |
| T1598.003 Spearphishing Link |
GroupDragonfly | Dragonfly has used spearphishing with PDF attachments containing malicious links that redirected to credential harvesting websites. |
| T1608.004 Drive-by Target |
GroupDragonfly | Dragonfly has compromised websites to redirect traffic and to host exploit kits. |
| T1685.005 Clear Windows Event Logs |
GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| T1686 Disable or Modify System Firewall |
GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.