Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupToddyCat | ToddyCat has run scripts to collect documents from targeted hosts. |
| T1018 Remote System Discovery |
GroupToddyCat | ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery. |
| T1021.002 SMB/Windows Admin Shares |
GroupToddyCat | ToddyCat has used locally mounted network shares for lateral movement through targated environments. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupToddyCat | ToddyCat has used the name `debug.exe` for malware components. |
| T1047 Windows Management Instrumentation |
GroupToddyCat | ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1049 System Network Connections Discovery |
GroupToddyCat | ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1053.005 Scheduled Task |
GroupToddyCat | ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection. |
| T1057 Process Discovery |
GroupToddyCat | ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1059.001 PowerShell |
GroupToddyCat | ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.003 Windows Command Shell |
GroupToddyCat | ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts. |
| T1069.002 Domain Groups |
GroupToddyCat | ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines. |
| T1074.002 Remote Data Staging |
GroupToddyCat | ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
| T1078.002 Domain Accounts |
GroupToddyCat | ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1083 File and Directory Discovery |
GroupToddyCat | ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension. |
| T1087.002 Domain Account |
GroupToddyCat | ToddyCat has run `net user %USER% /dom` for account discovery. |
| T1095 Non-Application Layer Protocol |
GroupToddyCat | ToddyCat has used a passive backdoor that receives commands with UDP packets. |
| T1106 Native API |
GroupToddyCat | ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts. |
| T1190 Exploit Public-Facing Application |
GroupToddyCat | ToddyCat has exploited the ProxyLogon vulnerability (CVE-2021-26855) to compromise Exchange Servers at multiple organizations. |
| T1518.001 Security Software Discovery |
GroupToddyCat | ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`. |
| T1560.001 Archive via Utility |
GroupToddyCat | ToddyCat has leveraged xcopy, 7zip, and RAR to stage and compress collected documents prior to exfiltration. |
| T1564.003 Hidden Window |
GroupToddyCat | ToddyCat has hidden malicious scripts using `powershell.exe -windowstyle hidden`. |
| T1566.003 Spearphishing via Service |
GroupToddyCat | ToddyCat has sent loaders configured to run Ninja as zip archives via Telegram. |
| T1567.002 Exfiltration to Cloud Storage |
GroupToddyCat | ToddyCat has used a DropBox uploader to exfiltrate stolen files. |
| T1680 Local Storage Discovery |
GroupToddyCat | ToddyCat has collected information on bootable drives including model, vendor, and serial numbers. |
| T1686 Disable or Modify System Firewall |
GroupToddyCat | Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.