Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareElise | Elise executes |
| T1007 System Service Discovery |
MalwareEmbargo | Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`. |
| T1007 System Service Discovery |
MalwareIxeshe | Ixeshe can list running services. |
| T1007 System Service Discovery |
MalwareBlack Basta | Black Basta can check whether the service name `FAX` is present. |
| T1007 System Service Discovery |
MalwareRATANKBA | RATANKBA uses |
| T1007 System Service Discovery |
MalwareCobalt Strike | Cobalt Strike can enumerate services on compromised hosts. |
| T1007 System Service Discovery |
MalwareSUNBURST | SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1007 System Service Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of services on the infected host. |
| T1007 System Service Discovery |
MalwareREvil | REvil can enumerate active services. |
| T1007 System Service Discovery |
MalwareSysUpdate | SysUpdate can collect a list of services on a victim machine. |
| T1007 System Service Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1007 System Service Discovery |
MalwareLAMEHUG | LAMEHUG can gather service information on targeted systems. |
| T1007 System Service Discovery |
MalwareLookBack | LookBack can enumerate services on the victim machine. |
| T1007 System Service Discovery |
MalwareZxShell | ZxShell can check the services on the system. |
| T1007 System Service Discovery |
MalwareJPIN | JPIN can list running services. |
| T1007 System Service Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can check if it is running as a service on a compromised host. |
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1007 System Service Discovery |
MalwarejRAT | jRAT can list local services. |
| T1007 System Service Discovery |
MalwareComnie | Comnie runs the command: |
| T1007 System Service Discovery |
MalwareBitPaymer | BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| T1007 System Service Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to enumerate services. |
| T1007 System Service Discovery |
ToolNet | The |
| T1007 System Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can search for modifiable services that could be used for privilege escalation. |
| T1007 System Service Discovery |
ToolTasklist | Tasklist can be used to discover services running on a system. |
| T1007 System Service Discovery |
ToolPoshC2 | PoshC2 can enumerate service and service permission information. |
| T1008 Fallback Channels |
CampaignNight Dragon | During Night Dragon, threat actors used company extranet servers as secondary C2 servers. |
| T1008 Fallback Channels |
GroupAPT41 | APT41 used the Steam community page as a fallback mechanism for C2. |
| T1008 Fallback Channels |
GroupFIN7 | FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| T1008 Fallback Channels |
GroupUNC3886 | UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| T1008 Fallback Channels |
GroupOilRig | OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. |
| T1008 Fallback Channels |
GroupLazarus Group | Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| T1008 Fallback Channels |
MalwareTrickBot | TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1008 Fallback Channels |
MalwareBumblebee | Bumblebee can use backup C2 servers if the primary server fails. |
| T1008 Fallback Channels |
MalwareStuxnet | Stuxnet has the ability to generate new C2 domains. |
| T1008 Fallback Channels |
MalwareExaramel for Linux | Exaramel for Linux can attempt to find a new C2 server if it receives an error. |
| T1008 Fallback Channels |
MalwareWinMM | WinMM is usually configured with primary and backup domains for C2 communications. |
| T1008 Fallback Channels |
MalwareRainyDay | RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working. |
| T1008 Fallback Channels |
MalwareAppleSeed | AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| T1008 Fallback Channels |
MalwareTinyTurla | TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds. |
| T1008 Fallback Channels |
MalwareSslMM | SslMM has a hard-coded primary and backup C2 string. |
| T1008 Fallback Channels |
MalwareMachete | Machete has sent data over HTTP if FTP failed, and has also used a fallback server. |
| T1008 Fallback Channels |
MalwareHOPLIGHT | HOPLIGHT has multiple C2 channels in place in case one fails. |
| T1008 Fallback Channels |
MalwareInvisiMole | InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1008 Fallback Channels |
MalwareQUIETEXIT | QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails. |
| T1008 Fallback Channels |
MalwareRDAT | RDAT has used HTTP if DNS C2 communications were not functioning. |
| T1008 Fallback Channels |
MalwareKazuar | Kazuar can accept multiple URLs for C2 servers. |
| T1008 Fallback Channels |
MalwareNETEAGLE | NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000. |
| T1008 Fallback Channels |
MalwareFatDuke | FatDuke has used several C2 servers per targeted organization. |
| T1008 Fallback Channels |
MalwareBlackEnergy | BlackEnergy has the capability to communicate over a backup channel via plus.google.com. |
| T1008 Fallback Channels |
MalwareShimRat | ShimRat has used a secondary C2 location if the first was unavailable. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.