ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
GroupAPT38

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

T1049
System Network Connections Discovery
GroupGALLIUM

GALLIUM used netstat -oan to obtain information about the victim network connections.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1049
System Network Connections Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to display network connections: netstat -ano >> %temp%\download

T1049
System Network Connections Discovery
GroupVolt Typhoon

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.

T1049
System Network Connections Discovery
GroupAPT41

APT41 has enumerated IP addresses of network resources and used the netstat command as part of network reconnaissance. The group has also used a malware variant, HIGHNOON, to enumerate active RDP sessions.

T1049
System Network Connections Discovery
GroupmenuPass

menuPass has used net use to conduct connectivity checks to machines.

T1049
System Network Connections Discovery
GroupAPT32

APT32 used the netstat -anpo tcp command to display TCP connections on the victim's machine.

T1049
System Network Connections Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.

T1049
System Network Connections Discovery
GroupTeamTNT

TeamTNT has run netstat -anp to search for rival malware connections. TeamTNT has also used `libprocesshider` to modify /etc/ld.so.preload.

T1049
System Network Connections Discovery
GroupSandworm Team

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.

T1049
System Network Connections Discovery
GroupAndariel

Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.

T1049
System Network Connections Discovery
GroupMustang Panda

Mustang Panda has used netstat -ano to determine network connection information.

T1049
System Network Connections Discovery
GroupOilRig

OilRig has used netstat -an on a victim to get a listing of network connections.

T1049
System Network Connections Discovery
GroupTropic Trooper

Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts.

T1049
System Network Connections Discovery
GroupKe3chang

Ke3chang performs local network connection discovery using netstat.

T1049
System Network Connections Discovery
GroupAPT1

APT1 used the net use command to get a listing on network connections.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1049
System Network Connections Discovery
GroupPoseidon Group

Poseidon Group obtains and saves information about victim network interfaces and addresses.

T1049
System Network Connections Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `netstat` to identify system network connections.

T1049
System Network Connections Discovery
GroupChimera

Chimera has used netstat -ano | findstr EST to discover network connections.

T1049
System Network Connections Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports.

T1049
System Network Connections Discovery
GroupToddyCat

ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts.

T1049
System Network Connections Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

T1049
System Network Connections Discovery
GroupLazarus Group

Lazarus Group has used net use to identify and establish a network connection with a remote host.

T1049
System Network Connections Discovery
GroupINC Ransom

INC Ransom has used RDP to test network connections.

T1049
System Network Connections Discovery
GroupEarth Lusca

Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational”
(Event ID 1024) to obtain network information from RDP connections. Earth Lusca has also used netstat from a compromised system to obtain network connection information.

T1049
System Network Connections Discovery
GroupVelvet Ant

Velvet Ant has enumerated existing network connections on victim devices.

T1049
System Network Connections Discovery
GroupHEXANE

HEXANE has used netstat to monitor connections to specific ports.

T1049
System Network Connections Discovery
GroupMagic Hound

Magic Hound has used quser.exe to identify existing RDP connections.

T1049
System Network Connections Discovery
GroupThreat Group-3390

Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim.

T1049
System Network Connections Discovery
GroupFIN13

FIN13 has used `netstat` and other net commands for network reconnaissance efforts.

T1052.001
Exfiltration over USB
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks.

T1052.001
Exfiltration over USB
GroupTropic Trooper

Tropic Trooper has exfiltrated data using USB storage devices.

T1053.002
At
GroupAPT18

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.

T1053.002
At
GroupBRONZE BUTLER

BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement.

T1053.002
At
GroupThreat Group-3390

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.

T1053.003
Cron
GroupAPT38

APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1053.003
Cron
GroupAPT5

APT5 has made modifications to the crontab file including in `/var/cron/tabs/`.

T1053.005
Scheduled Task
GroupAPT38

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1053.005
Scheduled Task
GroupBlackByte

BlackByte created scheduled tasks for payload execution.

T1053.005
Scheduled Task
GroupGALLIUM

GALLIUM established persistence for PoisonIvy by created a scheduled task.

T1053.005
Scheduled Task
GroupAPT3

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

T1053.005
Scheduled Task
GroupKimsuky

Kimsuky has downloaded additional malware with scheduled tasks. Kimsuky has established persistence by creating a scheduled task named “ChromeUpdateTaskMachine” through the PowerShell cmdlet `Register-ScheduleTask` which was set to execute another PowerShell script once, then five minutes after its creation and periodically repeat every 30 minutes. Kimsuky has also set scheduled tasks that run periodically using the PT1M repetition pattern leveraging naming conventions of Anti-Virus software to include "AhnlabUpdate".

T1053.005
Scheduled Task
GroupPatchwork

A Patchwork file stealer can run a TaskScheduler DLL to add persistence.

T1053.005
Scheduled Task
GroupAPT41

APT41 used a compromised account to create a scheduled task on a system.

T1053.005
Scheduled Task
GroupDragonfly

Dragonfly has used scheduled tasks to automatically log out of created accounts every 8 hours as well as to execute malicious files.

T1053.005
Scheduled Task
GroupmenuPass

menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler.

T1053.005
Scheduled Task
GroupAPT32

APT32 has used scheduled tasks to persist on victim systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.