Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.002 Tool |
GroupAPT38 | APT38 has obtained and used open-source tools such as Mimikatz. |
| T1685 Disable or Modify Tools |
GroupAPT38 | APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools. |
| T1685.005 Clear Windows Event Logs |
GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
| T1686 Disable or Modify System Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686.002 Network Device Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1690 Prevent Command History Logging |
GroupAPT38 | APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.