Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1132.002 Non-Standard Encoding |
MalwareCyclops Blink | Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed. |
| T1132.002 Non-Standard Encoding |
MalwareNeo-reGeorg | Neo-reGeorg can use modified Base64 encoding to obfuscate communications. |
| T1132.002 Non-Standard Encoding |
MalwarePowGoop | PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server. |
| T1132.002 Non-Standard Encoding |
MalwareShadowPad | ShadowPad has encoded data as readable Latin characters. |
| T1132.002 Non-Standard Encoding |
MalwareLizar | Lizar has used a complex XOR operation to obfuscate C2 communications. |
| T1132.002 Non-Standard Encoding |
MalwareBACKSPACE | Newer variants of BACKSPACE will encode C2 communications with a custom system. |
| T1132.002 Non-Standard Encoding |
MalwareSmall Sieve | Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic. |
| T1133 External Remote Services |
MalwareLinux Rabbit | Linux Rabbit attempts to gain access to the server via SSH. |
| T1133 External Remote Services |
MalwareMafalda | Mafalda can establish an SSH connection from a compromised host to a server. |
| T1133 External Remote Services |
MalwareHildegard | Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment. |
| T1133 External Remote Services |
MalwareDoki | Doki was executed through an open Docker daemon API port. |
| T1133 External Remote Services |
MalwareKinsing | Kinsing was executed in an Ubuntu container deployed via an open Docker daemon API. |
| T1134 Access Token Manipulation |
MalwareAppleSeed | AppleSeed can gain system level privilege by passing |
| T1134 Access Token Manipulation |
MalwareSslMM | SslMM contains a feature to manipulate process privileges and tokens. |
| T1134 Access Token Manipulation |
MalwareMafalda | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges. |
| T1134 Access Token Manipulation |
MalwareBlackCat | BlackCat has the ability modify access tokens. |
| T1134 Access Token Manipulation |
MalwareCuba | Cuba has used |
| T1134 Access Token Manipulation |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can adjust token privileges. |
| T1134 Access Token Manipulation |
MalwareSagerunex | Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread. |
| T1134 Access Token Manipulation |
MalwareMegaCortex | MegaCortex can enable |
| T1134 Access Token Manipulation |
MalwareRyuk | Ryuk has attempted to adjust its token privileges to have the |
| T1134 Access Token Manipulation |
MalwareHermeticWiper | HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`. |
| T1134 Access Token Manipulation |
MalwareSUNSPOT | SUNSPOT modified its security token to grants itself debugging privileges by adding |
| T1134 Access Token Manipulation |
MalwareKillDisk | KillDisk has attempted to get the access token of a process by calling |
| T1134 Access Token Manipulation |
MalwareQilin | Qilin can use an embedded Mimikatz module for token manipulation. |
| T1134 Access Token Manipulation |
MalwareGelsemium | Gelsemium can use token manipulation to bypass UAC on Windows7 systems. |
| T1134 Access Token Manipulation |
ToolSliver | Sliver has the ability to manipulate user tokens on targeted Windows systems. |
| T1134 Access Token Manipulation |
ToolPowerSploit | PowerSploit's |
| T1134 Access Token Manipulation |
ToolEmpire | Empire can use PowerSploit's |
| T1134 Access Token Manipulation |
ToolPoshC2 | PoshC2 can use Invoke-TokenManipulation for manipulating tokens. |
| T1134 Access Token Manipulation |
MalwareDuqu | Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges. |
| T1134.001 Token Impersonation/Theft |
MalwareStuxnet | Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager. |
| T1134.001 Token Impersonation/Theft |
MalwareHavoc | Havoc has a module capable of token impersonation. |
| T1134.001 Token Impersonation/Theft |
MalwareAria-body | Aria-body has the ability to duplicate a token from ntprint.exe. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| T1134.001 Token Impersonation/Theft |
MalwareBADHATCH | BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token. |
| T1134.001 Token Impersonation/Theft |
MalwareOkrum | Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API. |
| T1134.001 Token Impersonation/Theft |
MalwareSiloscape | Siloscape impersonates the main thread of |
| T1134.001 Token Impersonation/Theft |
MalwareFooder | Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| T1134.001 Token Impersonation/Theft |
MalwareLP-Notes | LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API. |
| T1134.001 Token Impersonation/Theft |
MalwareShamoon | Shamoon can impersonate tokens using |
| T1134.001 Token Impersonation/Theft |
MalwareTarrask | Tarrask leverages token theft to obtain `lsass.exe` security permissions. |
| T1134.001 Token Impersonation/Theft |
MalwareFinFisher | FinFisher uses token manipulation with NtFilterToken as part of UAC bypass. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
| T1134.001 Token Impersonation/Theft |
MalwareREvil | REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user. |
| T1134.001 Token Impersonation/Theft |
MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| T1134.001 Token Impersonation/Theft |
ToolSILENTTRINITY | SILENTTRINITY can find a process owned by a specific user and impersonate the associated token. |
| T1134.001 Token Impersonation/Theft |
ToolPupy | Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate. |
| T1134.002 Create Process with Token |
MalwareBankshot | Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user. |
| T1134.002 Create Process with Token |
MalwareTONESHELL | TONESHELL included functionality to create sub-processes with a specific user’s token. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.