Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAquatic Panda | Aquatic Panda has attempted to harvest credentials through LSASS memory dumping. |
| T1005 Data from Local System |
GroupAquatic Panda | Aquatic Panda captured local Windows security event log data from victim machines using the |
| T1007 System Service Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| T1021 Remote Services |
GroupAquatic Panda | Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions. |
| T1021.001 Remote Desktop Protocol |
GroupAquatic Panda | Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupAquatic Panda | Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| T1021.004 SSH |
GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1027.010 Command Obfuscation |
GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| T1033 System Owner/User Discovery |
GroupAquatic Panda | Aquatic Panda gathers information on recently logged-in users on victim devices. |
| T1036.004 Masquerade Task or Service |
GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAquatic Panda | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1047 Windows Management Instrumentation |
GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| T1059.001 PowerShell |
GroupAquatic Panda | Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell. |
| T1059.003 Windows Command Shell |
GroupAquatic Panda | Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to |
| T1059.004 Unix Shell |
GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| T1070.003 Clear Command History |
GroupAquatic Panda | Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations. |
| T1070.004 File Deletion |
GroupAquatic Panda | Aquatic Panda has deleted malicious executables from compromised machines. |
| T1078.002 Domain Accounts |
GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| T1082 System Information Discovery |
GroupAquatic Panda | Aquatic Panda has used native OS commands to understand privilege levels and system details. |
| T1087 Account Discovery |
GroupAquatic Panda | Aquatic Panda used the |
| T1105 Ingress Tool Transfer |
GroupAquatic Panda | Aquatic Panda has downloaded additional malware onto compromised hosts. |
| T1112 Modify Registry |
GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| T1218.011 Rundll32 |
GroupAquatic Panda | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary. |
| T1518.001 Security Software Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| T1543.003 Windows Service |
GroupAquatic Panda | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change. |
| T1550.002 Pass the Hash |
GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| T1560.001 Archive via Utility |
GroupAquatic Panda | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration. |
| T1574.001 DLL |
GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| T1574.006 Dynamic Linker Hijacking |
GroupAquatic Panda | Aquatic Panda modified the |
| T1588.001 Malware |
GroupAquatic Panda | Aquatic Panda has acquired and used njRAT in its operations. |
| T1588.002 Tool |
GroupAquatic Panda | Aquatic Panda has acquired and used Cobalt Strike in its operations. |
| T1595.002 Vulnerability Scanning |
GroupAquatic Panda | Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228). |
| T1654 Log Enumeration |
GroupAquatic Panda | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes. |
| T1685 Disable or Modify Tools |
GroupAquatic Panda | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems. |
| T1685.005 Clear Windows Event Logs |
GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.