Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.006 Timestomp |
MalwareElise | Elise performs timestomping of a CAB file it creates. |
| T1070.006 Timestomp |
MalwareGazer | For early Gazer versions, the compilation timestamp was faked. |
| T1070.006 Timestomp |
Malware3PARA RAT | 3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files. |
| T1070.006 Timestomp |
MalwareEVILNUM | EVILNUM has changed the creation date of files. |
| T1070.006 Timestomp |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can change the timestamp of specified filenames. |
| T1070.006 Timestomp |
MalwareShamoon | Shamoon can change the modified time for files to evade forensic detection. |
| T1070.006 Timestomp |
MalwareBPFDoor | BPFDoor uses the `utimes()` function to change the executable's timestamp. |
| T1070.006 Timestomp |
MalwareAttor | Attor has manipulated the time of last access to files and registry keys after they have been created or modified. |
| T1070.006 Timestomp |
MalwareNightClub | NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll. |
| T1070.006 Timestomp |
MalwareDerusbi | The Derusbi malware supports timestomping. |
| T1070.006 Timestomp |
MalwareKobalos | Kobalos can modify timestamps of replaced files, such as |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1070.006 Timestomp |
MalwareOwaAuth | OwaAuth has a command to timestop a file or directory. |
| T1070.006 Timestomp |
MalwareCobalt Strike | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1070.006 Timestomp |
MalwareUSBStealer | USBStealer sets the timestamps of its dropper files to the last-access and last-write timestamps of a standard Windows library chosen on the system. |
| T1070.006 Timestomp |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D can use the |
| T1070.006 Timestomp |
MalwareCyclops Blink | Cyclops Blink has the ability to use the Linux API function `utime` to change the timestamps of modified firmware update images. |
| T1070.006 Timestomp |
MalwareMacMa | MacMa has the capability to create and modify file timestamps. |
| T1070.006 Timestomp |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has updated the timestamp using the `touch` command. |
| T1070.006 Timestomp |
MalwareWinnti for Windows | Winnti for Windows can set the timestamps for its worker and service components to match that of cmd.exe. |
| T1070.006 Timestomp |
MalwarePowerStallion | PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file. |
| T1070.006 Timestomp |
MalwaremetaMain | metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges. |
| T1070.006 Timestomp |
MalwarePsylo | Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory. |
| T1070.006 Timestomp |
MalwareGelsemium | Gelsemium has the ability to perform timestomping of files on targeted systems. |
| T1070.006 Timestomp |
MalwareBitPaymer | BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| T1070.006 Timestomp |
MalwareFALLCHILL | FALLCHILL can modify file or directory timestamps. |
| T1070.006 Timestomp |
ToolEmpire | Empire can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1070.007 Clear Network Connection History and Configurations |
CampaignRedPenguin | During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices. |
| T1070.007 Clear Network Connection History and Configurations |
GroupVolt Typhoon | Volt Typhoon has inspected server logs to remove their IPs. |
| T1070.007 Clear Network Connection History and Configurations |
GroupUNC3886 | UNC3886 has cleared specific events that contained the threat actor’s IP address from multiple log sources. |
| T1070.007 Clear Network Connection History and Configurations |
MalwareSUNBURST | SUNBURST also removed the firewall rules it created during execution. |
| T1070.008 Clear Mailbox Data |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`. |
| T1070.008 Clear Mailbox Data |
GroupScattered Spider | Scattered Spider has manually deleted emails notifying users of suspicious account activity. |
| T1070.008 Clear Mailbox Data |
GroupAPT42 | APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| T1070.008 Clear Mailbox Data |
MalwareLunarMail | LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration. |
| T1070.008 Clear Mailbox Data |
MalwareGoopy | Goopy has the ability to delete emails used for C2 once the content has been copied. |
| T1070.009 Clear Persistence |
MalwareMisdat | Misdat is capable of deleting Registry keys used for persistence. |
| T1070.009 Clear Persistence |
MalwareRaspberry Robin | Raspberry Robin uses a |
| T1070.009 Clear Persistence |
MalwareSplatDropper | SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices. |
| T1070.009 Clear Persistence |
MalwarePlugX | PlugX has deleted registry keys that store data and maintained persistence. |
| T1070.009 Clear Persistence |
MalwareS-Type | S-Type has deleted accounts it has created. |
| T1070.009 Clear Persistence |
MalwareRTM | RTM has the ability to remove Registry entries that it created for persistence. |
| T1070.009 Clear Persistence |
MalwareBazar | Bazar's loader can delete scheduled tasks created by a previous instance of the malware. |
| T1070.009 Clear Persistence |
MalwareKapeka | Kapeka will clear registry values used for persistent configuration storage when uninstalled. |
| T1070.009 Clear Persistence |
MalwareSUNBURST | SUNBURST removed IFEO registry values to clean up traces of persistence. |
| T1070.009 Clear Persistence |
MalwareIPsec Helper | IPsec Helper can delete various service traces related to persistent execution when commanded. |
| T1070.009 Clear Persistence |
MalwarePillowmint | Pillowmint can uninstall the malicious service from an infected machine. |
| T1070.009 Clear Persistence |
MalwareGrimAgent | GrimAgent can delete previously created tasks on a compromised host. |
| T1070.009 Clear Persistence |
MalwarenjRAT | njRAT is capable of manipulating and deleting registry keys, including those used for persistence. |
| T1070.009 Clear Persistence |
MalwareKOCTOPUS | KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.