Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareQakBot | QakBot can identify remote systems through the |
| T1018 Remote System Discovery |
MalwareComnie | Comnie runs the |
| T1018 Remote System Discovery |
MalwareOSInfo | OSInfo performs a connection test to discover remote systems in the network |
| T1018 Remote System Discovery |
MalwareBitPaymer | BitPaymer can use |
| T1018 Remote System Discovery |
MalwareHermeticWizard | HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.` |
| T1018 Remote System Discovery |
ToolNet | Commands such as |
| T1018 Remote System Discovery |
ToolBloodHound | BloodHound can enumerate and collect the properties of domain computers, including domain controllers. |
| T1018 Remote System Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate and collect the properties of domain computers. |
| T1018 Remote System Discovery |
ToolArp | Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems. |
| T1018 Remote System Discovery |
ToolROADTools | ROADTools can enumerate Azure AD systems and devices. |
| T1018 Remote System Discovery |
ToolNltest | Nltest may be used to enumerate remote domain controllers using options such as |
| T1018 Remote System Discovery |
ToolNBTscan | NBTscan can list NetBIOS computer names. |
| T1018 Remote System Discovery |
ToolPing | Ping can be used to identify remote systems within a network. |
| T1018 Remote System Discovery |
ToolCrackMapExec | CrackMapExec can discover active IP addresses, along with the machine name, within a targeted network. |
| T1018 Remote System Discovery |
ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| T1018 Remote System Discovery |
MalwareCanisterWorm | CanisterWorm has scanned the local /24 subnet for new targets. |
| T1020 Automated Exfiltration |
MalwareStrongPity | StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1020 Automated Exfiltration |
MalwareHannotog | Hannotog can upload encyrpted data for exfiltration. |
| T1020 Automated Exfiltration |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files automatically over FTP to remote servers. |
| T1020 Automated Exfiltration |
MalwareMachete | Machete’s collected files are exfiltrated automatically to remote servers. |
| T1020 Automated Exfiltration |
MalwareDoki | Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL. |
| T1020 Automated Exfiltration |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe. |
| T1020 Automated Exfiltration |
MalwareLightNeuron | LightNeuron can be configured to automatically exfiltrate files under a specified directory. |
| T1020 Automated Exfiltration |
MalwarePeppy | Peppy has the ability to automatically exfiltrate files and keylogs. |
| T1020 Automated Exfiltration |
MalwareTINYTYPHON | When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server. |
| T1020 Automated Exfiltration |
MalwareAttor | Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| T1020 Automated Exfiltration |
MalwareCrutch | Crutch has automatically exfiltrated stolen files to Dropbox. |
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1020 Automated Exfiltration |
MalwareUSBStealer | USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine. |
| T1020 Automated Exfiltration |
MalwareTajMahal | TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2. |
| T1020 Automated Exfiltration |
MalwareRaccoon Stealer | Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes. |
| T1020 Automated Exfiltration |
MalwareSolar | Solar can automatically exfitrate files from compromised systems. |
| T1020 Automated Exfiltration |
MalwareOutSteel | OutSteel can automatically upload collected files to its C2 server. |
| T1020 Automated Exfiltration |
MalwareEbury | If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record. |
| T1020 Automated Exfiltration |
ToolShimRatReporter | ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2. |
| T1020 Automated Exfiltration |
ToolEmpire | Empire has the ability to automatically send collected data back to the threat actors' C2. |
| T1020 Automated Exfiltration |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there. |
| T1021 Remote Services |
MalwareStuxnet | Stuxnet can propagate via peer-to-peer communication and updates using RPC. |
| T1021 Remote Services |
MalwareKivars | Kivars has the ability to remotely trigger keyboard input and mouse clicks. |
| T1021 Remote Services |
MalwareMacMa | MacMa can manage remote screen sessions. |
| T1021 Remote Services |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use RPC for lateral movement. |
| T1021.001 Remote Desktop Protocol |
MalwarereGeorg | reGeorg can be used to tunnel RDP connections. |
| T1021.001 Remote Desktop Protocol |
MalwareDarkComet | DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard. |
| T1021.001 Remote Desktop Protocol |
MalwarezwShell | zwShell has used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
MalwareCarbanak | Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions. |
| T1021.001 Remote Desktop Protocol |
MalwareSDBbot | SDBbot has the ability to use RDP to connect to victim's machines. |
| T1021.001 Remote Desktop Protocol |
MalwarePysa | Pysa has laterally moved using RDP connections. |
| T1021.001 Remote Desktop Protocol |
MalwareCobalt Strike | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| T1021.001 Remote Desktop Protocol |
MalwareServHelper | ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel. |
| T1021.001 Remote Desktop Protocol |
MalwareRevenge RAT | Revenge RAT has a plugin to perform RDP access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.