Real-world descriptions of how a group, tool or campaign used a technique.
55 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1609 Container Administration Command |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`. |
| T1614 System Location Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings. |
| T1614.001 System Language Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language. |
| T1649 Steal or Forge Authentication Certificates |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments. |
| T1677 Poisoned Pipeline Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.