Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
GroupAPT38 | APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1049 System Network Connections Discovery |
GroupGALLIUM | GALLIUM used |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1049 System Network Connections Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1049 System Network Connections Discovery |
GroupAPT41 | APT41 has enumerated IP addresses of network resources and used the |
| T1049 System Network Connections Discovery |
GroupmenuPass | menuPass has used |
| T1049 System Network Connections Discovery |
GroupAPT32 | APT32 used the |
| T1049 System Network Connections Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1049 System Network Connections Discovery |
GroupTeamTNT | TeamTNT has run |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1049 System Network Connections Discovery |
GroupAndariel | Andariel has used the |
| T1049 System Network Connections Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1049 System Network Connections Discovery |
GroupOilRig | OilRig has used |
| T1049 System Network Connections Discovery |
GroupTropic Trooper | Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1049 System Network Connections Discovery |
GroupAPT1 | APT1 used the |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1049 System Network Connections Discovery |
GroupPoseidon Group | Poseidon Group obtains and saves information about victim network interfaces and addresses. |
| T1049 System Network Connections Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1049 System Network Connections Discovery |
GroupChimera | Chimera has used |
| T1049 System Network Connections Discovery |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports. |
| T1049 System Network Connections Discovery |
GroupToddyCat | ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1049 System Network Connections Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| T1049 System Network Connections Discovery |
GroupLazarus Group | Lazarus Group has used |
| T1049 System Network Connections Discovery |
GroupINC Ransom | INC Ransom has used RDP to test network connections. |
| T1049 System Network Connections Discovery |
GroupEarth Lusca | Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” |
| T1049 System Network Connections Discovery |
GroupVelvet Ant | Velvet Ant has enumerated existing network connections on victim devices. |
| T1049 System Network Connections Discovery |
GroupHEXANE | HEXANE has used netstat to monitor connections to specific ports. |
| T1049 System Network Connections Discovery |
GroupMagic Hound | Magic Hound has used quser.exe to identify existing RDP connections. |
| T1049 System Network Connections Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim. |
| T1049 System Network Connections Discovery |
GroupFIN13 | FIN13 has used `netstat` and other net commands for network reconnaissance efforts. |
| T1052.001 Exfiltration over USB |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks. |
| T1052.001 Exfiltration over USB |
GroupTropic Trooper | Tropic Trooper has exfiltrated data using USB storage devices. |
| T1053.002 At |
GroupAPT18 | APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network. |
| T1053.002 At |
GroupBRONZE BUTLER | BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| T1053.002 At |
GroupThreat Group-3390 | Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network. |
| T1053.003 Cron |
GroupAPT38 | APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| T1053.003 Cron |
GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| T1053.003 Cron |
GroupAPT5 | APT5 has made modifications to the crontab file including in `/var/cron/tabs/`. |
| T1053.005 Scheduled Task |
GroupAPT38 | APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| T1053.005 Scheduled Task |
GroupBlackByte | BlackByte created scheduled tasks for payload execution. |
| T1053.005 Scheduled Task |
GroupGALLIUM | GALLIUM established persistence for PoisonIvy by created a scheduled task. |
| T1053.005 Scheduled Task |
GroupAPT3 | An APT3 downloader creates persistence by creating the following scheduled task: |
| T1053.005 Scheduled Task |
GroupKimsuky | Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate". |
| T1053.005 Scheduled Task |
GroupPatchwork | A Patchwork file stealer can run a TaskScheduler DLL to add persistence. |
| T1053.005 Scheduled Task |
GroupAPT41 | APT41 used a compromised account to create a scheduled task on a system. |
| T1053.005 Scheduled Task |
GroupDragonfly | Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files. |
| T1053.005 Scheduled Task |
GroupmenuPass | menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler. |
| T1053.005 Scheduled Task |
GroupAPT32 | APT32 has used scheduled tasks to persist on victim systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.