ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0082×

56 examples

TechniqueUsed byProcedure example
T1588.002
Tool
GroupAPT38

APT38 has obtained and used open-source tools such as Mimikatz.

T1685
Disable or Modify Tools
GroupAPT38

APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools.

T1685.005
Clear Windows Event Logs
GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

T1686
Disable or Modify System Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686.002
Network Device Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1690
Prevent Command History Logging
GroupAPT38

APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.