ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0139×

56 examples

TechniqueUsed byProcedure example
T1611
Escape to Host
GroupTeamTNT

TeamTNT has deployed privileged containers that mount the filesystem of victim machine.

T1613
Container and Resource Discovery
GroupTeamTNT

TeamTNT has checked for running containers with docker ps and for specific container names with docker inspect. TeamTNT has also searched for Kubernetes pods running in a local network.

T1680
Local Storage Discovery
GroupTeamTNT

TeamTNT has searched for disk partition and logical volume information.

T1685
Disable or Modify Tools
GroupTeamTNT

TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure.

T1685.006
Clear Linux or Mac System Logs
GroupTeamTNT

TeamTNT has removed system logs from /var/log/syslog.

T1686
Disable or Modify System Firewall
GroupTeamTNT

TeamTNT has disabled iptables.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.