Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1069.002 Domain Groups |
Tooldsquery | dsquery can be used to gather information on permission groups within a domain. |
| T1069.002 Domain Groups |
ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1069.002 Domain Groups |
ToolCrackMapExec | CrackMapExec can gather the user accounts within domain groups. |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
| T1069.003 Cloud Groups |
CampaignC0027 | During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes. |
| T1069.003 Cloud Groups |
ToolPacu | Pacu can enumerate IAM permissions. |
| T1069.003 Cloud Groups |
ToolAADInternals | AADInternals can enumerate Azure AD groups. |
| T1069.003 Cloud Groups |
ToolROADTools | ROADTools can enumerate Azure AD groups. |
| T1069.003 Cloud Groups |
GroupShinyHunters | ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts. |
| T1070 Indicator Removal |
CampaignCutting Edge | During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887. |
| T1070 Indicator Removal |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file. |
| T1070 Indicator Removal |
GroupMustang Panda | Mustang Panda has deleted registry keys that store data and maintained persistence. |
| T1070 Indicator Removal |
GroupAPT42 | APT42 has cleared Chrome browser history. |
| T1070 Indicator Removal |
GroupAPT5 | APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| T1070 Indicator Removal |
GroupLazarus Group | Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked. |
| T1070 Indicator Removal |
MalwareOrz | Orz can overwrite Registry settings to reduce its visibility on the victim. |
| T1070 Indicator Removal |
MalwareStuxnet | Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads. |
| T1070 Indicator Removal |
MalwareIronWind | IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems. |
| T1070 Indicator Removal |
MalwareSardonic | Sardonic has the ability to delete created WMI objects to evade detections. |
| T1070 Indicator Removal |
MalwareBankshot | Bankshot deletes all artifacts associated with the malware from the infected machine. |
| T1070 Indicator Removal |
MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070 Indicator Removal |
MalwareNeoichor | Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key. |
| T1070 Indicator Removal |
MalwareBlackEnergy | BlackEnergy has removed the watermark associated with enabling the |
| T1070 Indicator Removal |
MalwareRising Sun | Rising Sun can clear a memory blog in the process by overwriting it with junk bytes. |
| T1070 Indicator Removal |
MalwareFlagpro | Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. |
| T1070 Indicator Removal |
MalwareDarkWatchman | DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history. |
| T1070 Indicator Removal |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script to clear file system cache memory via the |
| T1070 Indicator Removal |
MalwareEVILNUM | EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| T1070 Indicator Removal |
MalwareMetamorfo | Metamorfo has a command to delete a Registry key it uses, |
| T1070 Indicator Removal |
MalwareBPFDoor | BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process. |
| T1070 Indicator Removal |
MalwareSDBbot | SDBbot has the ability to clean up and remove data structures from a compromised host. |
| T1070 Indicator Removal |
MalwareSibot | Sibot will delete an associated registry key if a certain server response is received. |
| T1070 Indicator Removal |
MalwareHermeticWiper | HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070 Indicator Removal |
MalwareSUNBURST | SUNBURST removed HTTP proxy registry values to clean up traces of execution. |
| T1070 Indicator Removal |
MalwareIPsec Helper | IPsec Helper can delete various registry keys related to its execution and use. |
| T1070 Indicator Removal |
MalwareFunnyDream | FunnyDream has the ability to clean traces of malware deployment. |
| T1070 Indicator Removal |
MalwareMaze | Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1070 Indicator Removal |
MalwareShadowPad | ShadowPad has deleted arbitrary Registry values. |
| T1070 Indicator Removal |
ToolSILENTTRINITY | SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys. |
| T1070 Indicator Removal |
ToolCSPY Downloader | CSPY Downloader has the ability to remove values it writes to the Registry. |
| T1070 Indicator Removal |
ToolRemcos | Remcos can clean saved cookies and logins from the web browser. |
| T1070 Indicator Removal |
ToolDonut | Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
| T1070.003 Clear Command History |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by deleting Bash histories. |
| T1070.003 Clear Command History |
GroupmenuPass | menuPass has used Wevtutil to remove PowerShell execution logs. |
| T1070.003 Clear Command History |
GroupTeamTNT | TeamTNT has cleared command history with |
| T1070.003 Clear Command History |
GroupAquatic Panda | Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations. |
| T1070.003 Clear Command History |
GroupMedusa Group | Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`. |
| T1070.003 Clear Command History |
GroupAPT5 | APT5 has cleared the command history on targeted ESXi servers. |
| T1070.003 Clear Command History |
GroupLazarus Group | Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility. |
| T1070.003 Clear Command History |
GroupMagic Hound | Magic Hound has removed mailbox export requests from compromised Exchange servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.