Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
MalwareMis-Type | Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`. |
| T1106 Native API |
MalwareKillDisk | KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine. |
| T1106 Native API |
MalwareQilin | Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery. |
| T1106 Native API |
MalwareKevin | Kevin can use the `ShowWindow` API to avoid detection. |
| T1106 Native API |
MalwareStarProxy | StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data. |
| T1106 Native API |
MalwareBADNEWS | BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute. |
| T1106 Native API |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name via |
| T1106 Native API |
MalwareQakBot | QakBot can use |
| T1106 Native API |
MalwareDOWNIISSA | DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources. |
| T1106 Native API |
MalwareHancitor | Hancitor has used |
| T1106 Native API |
MalwareGelsemium | Gelsemium has the ability to use various Windows API functions to perform tasks. |
| T1106 Native API |
MalwareDridex | Dridex has used the |
| T1106 Native API |
MalwareBBK | BBK has the ability to use the |
| T1106 Native API |
MalwareDenis | Denis used the |
| T1106 Native API |
MalwareINC Ransomware | INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots. |
| T1106 Native API |
MalwareSplatCloak | SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`. |
| T1106 Native API |
MalwareWaterbear | Waterbear can leverage API functions for execution. |
| T1106 Native API |
MalwareLizar | Lizar has used various Windows API functions on a victim's machine. |
| T1106 Native API |
MalwareBitPaymer | BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including |
| T1106 Native API |
MalwareADVSTORESHELL | ADVSTORESHELL is capable of starting a process using CreateProcess. |
| T1106 Native API |
MalwareStrifeWater | StrifeWater can use a variety of APIs for execution. |
| T1106 Native API |
MalwareWarzoneRAT | WarzoneRAT can use a variety of API calls on a compromised host. |
| T1106 Native API |
MalwareHermeticWizard | HermeticWizard can connect to remote shares using `WNetAddConnection2W`. |
| T1106 Native API |
ToolBloodHound | BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data. |
| T1106 Native API |
ToolShimRatReporter | ShimRatReporter used several Windows API functions to gather information from the infected system. |
| T1106 Native API |
ToolSILENTTRINITY | SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`. |
| T1106 Native API |
ToolEmpire | Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks. |
| T1106 Native API |
ToolPcShare | PcShare has used a variety of Windows API functions. |
| T1106 Native API |
ToolAsyncRAT | AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| T1106 Native API |
ToolBrute Ratel C4 | Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion. |
| T1106 Native API |
ToolImminent Monitor | Imminent Monitor has leveraged CreateProcessW() call to execute the debugger. |
| T1106 Native API |
ToolDonut | Donut code modules use various API functions to load and inject code. |
| T1106 Native API |
MalwareZeroCleare | ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory. |
| T1110 Brute Force |
MalwareChaos | Chaos conducts brute force attacks against SSH services to gain initial access. |
| T1110 Brute Force |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to perform brute force attacks on a system. |
| T1110 Brute Force |
MalwarePysa | Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts. |
| T1110 Brute Force |
MalwareKinsing | Kinsing has attempted to brute force hosts over SSH. |
| T1110 Brute Force |
MalwareQakBot | QakBot can conduct brute force attacks to capture credentials. |
| T1110 Brute Force |
ToolPoshC2 | PoshC2 has modules for brute forcing local administrator and AD user accounts. |
| T1110 Brute Force |
ToolCrackMapExec | CrackMapExec can brute force supplied user credentials across a network range. |
| T1110.001 Password Guessing |
MalwarePony | Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| T1110.001 Password Guessing |
MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| T1110.001 Password Guessing |
MalwareP.A.S. Webshell | P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services. |
| T1110.001 Password Guessing |
MalwareLucifer | Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords. |
| T1110.001 Password Guessing |
MalwareChina Chopper | China Chopper's server component can perform brute force password guessing against authentication portals. |
| T1110.001 Password Guessing |
MalwareXbash | Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports. |
| T1110.001 Password Guessing |
MalwareSpeakUp | SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels. |
| T1110.001 Password Guessing |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares. |
| T1110.001 Password Guessing |
ToolCrackMapExec | CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
| T1110.002 Password Cracking |
MalwareNet Crawler | Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.