Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareWinnti for Linux | Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity. |
| T1014 Rootkit |
MalwareHikit | |
| T1014 Rootkit |
MalwareDrovorub | Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view. |
| T1014 Rootkit |
MalwarePoisonIvy | PoisonIvy starts a rootkit from a malicious file dropped to disk. |
| T1014 Rootkit |
MalwareLoJax | LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems. |
| T1014 Rootkit |
MalwareRamsay | Ramsay has included a rootkit to evade defenses. |
| T1014 Rootkit |
MalwareCarberp | Carberp has used user mode rootkit techniques to remain hidden on the system. |
| T1014 Rootkit |
MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| T1014 Rootkit |
MalwareHIDEDRV | HIDEDRV is a rootkit that hides certain operating system artifacts. |
| T1014 Rootkit |
MalwareHiddenWasp | HiddenWasp uses a rootkit to hook and implement functions on the system. |
| T1014 Rootkit |
MalwareWarzoneRAT | WarzoneRAT can include a rootkit to hide processes, files, and startup. |
| T1014 Rootkit |
ToolHTRAN | HTRAN can install a rootkit to hide network connections from the host OS. |
| T1016 System Network Configuration Discovery |
MalwareTrickBot | TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine. |
| T1016 System Network Configuration Discovery |
Malwarecd00r | cd00r can discover the IP for the network interface on the compromised device. |
| T1016 System Network Configuration Discovery |
MalwarePowerDuke | PowerDuke has a command to get the victim's domain and NetBIOS name. |
| T1016 System Network Configuration Discovery |
MalwareEKANS | EKANS can determine the domain of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected the victim machine's local IP address information and MAC address. |
| T1016 System Network Configuration Discovery |
MalwareNinja | Ninja can enumerate the IP address on compromised systems. |
| T1016 System Network Configuration Discovery |
MalwarePikabot | Pikabot gathers victim network information through commands such as |
| T1016 System Network Configuration Discovery |
MalwareAmadey | Amadey can identify the IP address of a victim machine. |
| T1016 System Network Configuration Discovery |
MalwareProxysvc | Proxysvc collects the network adapter information and domain/username information based on current remote sessions. |
| T1016 System Network Configuration Discovery |
MalwareOrz | Orz can gather victim proxy information. |
| T1016 System Network Configuration Discovery |
MalwareTorisma | Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address. |
| T1016 System Network Configuration Discovery |
MalwareNOKKI | NOKKI can gather information on the victim IP address. |
| T1016 System Network Configuration Discovery |
Malwareyty | yty runs |
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1016 System Network Configuration Discovery |
MalwareStuxnet | Stuxnet collects the IP address of a compromised system. |
| T1016 System Network Configuration Discovery |
MalwarePOWRUNER | POWRUNER may collect network configuration data by running |
| T1016 System Network Configuration Discovery |
MalwareKOPILUWAK | KOPILUWAK can use Arp to discover a target's network configuration setttings. |
| T1016 System Network Configuration Discovery |
MalwareSardonic | Sardonic has the ability to execute the `ipconfig` command. |
| T1016 System Network Configuration Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1016 System Network Configuration Discovery |
MalwareKEYMARBLE | KEYMARBLE gathers the MAC address of the victim’s machine. |
| T1016 System Network Configuration Discovery |
MalwareRedLeaves | RedLeaves can obtain information about network parameters. |
| T1016 System Network Configuration Discovery |
MalwareFelismus | Felismus collects the victim LAN IP address and sends it to the C2 server. |
| T1016 System Network Configuration Discovery |
MalwareGeminiDuke | GeminiDuke collects information on network settings and Internet proxy settings from the victim. |
| T1016 System Network Configuration Discovery |
MalwareHavoc | Havoc has a module for network enumeration including determining IP addresses. |
| T1016 System Network Configuration Discovery |
MalwareGravityRAT | GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name. |
| T1016 System Network Configuration Discovery |
MalwareInvisibleFerret | InvisibleFerret has collected the local IP address, and external IP. |
| T1016 System Network Configuration Discovery |
MalwareStrongPity | StrongPity can identify the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwarexCaon | xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address. |
| T1016 System Network Configuration Discovery |
MalwarePLAINTEE | PLAINTEE uses the |
| T1016 System Network Configuration Discovery |
MalwareOceanSalt | OceanSalt can collect the victim’s IP address. |
| T1016 System Network Configuration Discovery |
MalwareBrave Prince | Brave Prince gathers network configuration information as well as the ARP cache. |
| T1016 System Network Configuration Discovery |
MalwareAppleSeed | AppleSeed can identify the IP of a targeted system. |
| T1016 System Network Configuration Discovery |
MalwareNETWIRE | NETWIRE can collect the IP address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareJ-magic | J-magic can compare the host and remote IPs to check if a received packet is from the infected machine. |
| T1016 System Network Configuration Discovery |
MalwareiKitten | iKitten will look for the current IP address. |
| T1016 System Network Configuration Discovery |
MalwareGomir | Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses. |
| T1016 System Network Configuration Discovery |
MalwareAria-body | Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareOlympic Destroyer | Olympic Destroyer uses API calls to enumerate the infected system's ARP table. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.