Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
GroupFIN6 | FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1047 Windows Management Instrumentation |
GroupFIN7 | FIN7 has used WMI to install malware on targeted systems. |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1047 Windows Management Instrumentation |
GroupMustang Panda | Mustang Panda has executed PowerShell scripts via WMI. |
| T1047 Windows Management Instrumentation |
GroupTA2541 | TA2541 has used WMI to query targeted systems for security products. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| T1047 Windows Management Instrumentation |
GroupLeviathan | Leviathan has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe to set environment variables. |
| T1047 Windows Management Instrumentation |
GroupLotus Blossom | Lotus Blossom has used WMI to enable lateral movement. |
| T1047 Windows Management Instrumentation |
GroupStealth Falcon | Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI). |
| T1047 Windows Management Instrumentation |
GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1047 Windows Management Instrumentation |
GroupCinnamon Tempest | Cinnamon Tempest has used Impacket for lateral movement via WMI. |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1047 Windows Management Instrumentation |
GroupMirrorFace | MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1047 Windows Management Instrumentation |
GroupMedusa Group | Medusa Group has utilized Windows Management Instrumentation to query system information. |
| T1047 Windows Management Instrumentation |
GroupDeep Panda | The Deep Panda group is known to utilize WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
GroupEmber Bear | Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupWindshift | Windshift has used WMI to collect information about target machines. |
| T1047 Windows Management Instrumentation |
GroupToddyCat | ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1047 Windows Management Instrumentation |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
GroupAPT-C-36 | APT-C-36 has used WMI to execute PowerShell. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupEarth Lusca | Earth Lusca used a VBA script to execute WMI. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupVelvet Ant | Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI. |
| T1047 Windows Management Instrumentation |
GroupVOID MANTICORE | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1047 Windows Management Instrumentation |
GroupMagic Hound | Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
| T1047 Windows Management Instrumentation |
GroupThreat Group-3390 | A Threat Group-3390 tool can use WMI to execute a binary. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1047 Windows Management Instrumentation |
GroupFIN13 | FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines. |
| T1048 Exfiltration Over Alternative Protocol |
GroupTeamTNT | TeamTNT has sent locally staged files with collected credentials to C2 servers using cURL. |
| T1048 Exfiltration Over Alternative Protocol |
GroupPlay | Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupStorm-1811 | Storm-1811 has exfiltrated captured user credentials via Secure Copy Protocol (SCP). |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupCURIUM | CURIUM has used SMTPS to exfiltrate collected data from victims. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupMirrorFace | MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupAPT28 | APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupSalt Typhoon | Salt Typhoon has exfiltrated configuration files from exploited network devices over FTP and TFTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT32 | APT32's backdoor can exfiltrate data by encoding it in the subdomain field of DNS packets. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN6 | FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupMustang Panda | Mustang Panda has used FTP to exfiltrate archive files. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupContagious Interview | Contagious Interview has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupOilRig | OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupLazarus Group | Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupThrip | Thrip has used WinSCP to exfiltrate data from a targeted organization over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT33 | APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN8 | FIN8 has used FTP to exfiltrate collected data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.