Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.005 VNC |
MalwareProton | Proton uses VNC to connect into systems. |
| T1021.005 VNC |
MalwareZxShell | ZxShell supports functionality for VNC sessions. |
| T1021.005 VNC |
MalwareWarzoneRAT | WarzoneRAT has the ability of performing remote desktop access via a VNC console. |
| T1021.006 Windows Remote Management |
MalwareCobalt Strike | Cobalt Strike can use |
| T1021.006 Windows Remote Management |
ToolSILENTTRINITY | SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM. |
| T1021.006 Windows Remote Management |
ToolBrute Ratel C4 | Brute Ratel C4 can use WinRM for pivoting. |
| T1021.007 Cloud Services |
MalwareMini Shai-Hulud | Mini Shai-Hulud has accessed and propagated to AWS EC2 instances via SSM Send-Command. |
| T1025 Data from Removable Media |
MalwareGravityRAT | GravityRAT steals files based on an extension list if a USB drive is connected to the system. |
| T1025 Data from Removable Media |
MalwareAppleSeed | AppleSeed can find and collect data from removable media devices. |
| T1025 Data from Removable Media |
MalwareCosmicDuke | CosmicDuke steals user files from removable media with file extensions and keywords that match a predefined list. |
| T1025 Data from Removable Media |
MalwareAria-body | Aria-body has the ability to collect data from USB devices. |
| T1025 Data from Removable Media |
MalwareCrimson | Crimson contains a module to collect data from removable drives. |
| T1025 Data from Removable Media |
MalwareMachete | Machete can find, encrypt, and upload files from fixed and removable drives. |
| T1025 Data from Removable Media |
MalwarePrikormka | Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB. |
| T1025 Data from Removable Media |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on removable media and copies them to a staging area. The default file types copied would include data copied to the drive by SPACESHIP. |
| T1025 Data from Removable Media |
MalwareInvisiMole | InvisiMole can collect jpeg files from connected MTP devices. |
| T1025 Data from Removable Media |
MalwareObliqueRAT | ObliqueRAT has the ability to extract data from removable devices connected to the endpoint. |
| T1025 Data from Removable Media |
MalwareRemsec | Remsec has a package that collects documents from any inserted USB sticks. |
| T1025 Data from Removable Media |
MalwareExplosive | Explosive can scan all .exe files located in the USB drive. |
| T1025 Data from Removable Media |
MalwareRover | Rover searches for files on attached removable drives based on a predefined list of file extensions every five seconds. |
| T1025 Data from Removable Media |
MalwareCrutch | Crutch can monitor removable drives and exfiltrate files matching a given extension list. |
| T1025 Data from Removable Media |
MalwareMgBot | MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria. |
| T1025 Data from Removable Media |
MalwareUSBStealer | Once a removable media device is inserted back into the first victim, USBStealer collects data from it that was exfiltrated from a second victim. |
| T1025 Data from Removable Media |
MalwareTajMahal | TajMahal has the ability to steal written CD images and files of interest from previously connected removable drives when they become available again. |
| T1025 Data from Removable Media |
MalwareRamsay | Ramsay can collect data from removable media and stage it for exfiltration. |
| T1025 Data from Removable Media |
MalwareFunnyDream | The FunnyDream FilePakMonitor component has the ability to collect files from removable devices. |
| T1025 Data from Removable Media |
MalwareBADNEWS | BADNEWS copies files with certain extensions from USB devices to |
| T1027 Obfuscated Files or Information |
MalwareTrickBot | TrickBot uses non-descriptive names to hide functionality. |
| T1027 Obfuscated Files or Information |
MalwareEKANS | EKANS uses encoded strings in its process kill list. |
| T1027 Obfuscated Files or Information |
MalwareSynAck | SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1027 Obfuscated Files or Information |
MalwareBumblebee | Bumblebee has been delivered as password-protected zipped ISO files and used control-flow-flattening to obfuscate the flow of functions. |
| T1027 Obfuscated Files or Information |
MalwareBRICKSTORM | BRICKSTORM has utilized Go libraries to include Garble to obfuscate code. |
| T1027 Obfuscated Files or Information |
MalwareAmadey | Amadey has obfuscated strings such as antivirus vendor names, domains, files, and others. |
| T1027 Obfuscated Files or Information |
MalwareOrz | Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll. |
| T1027 Obfuscated Files or Information |
MalwareNOKKI | NOKKI uses Base64 encoding for strings. |
| T1027 Obfuscated Files or Information |
MalwareAvosLocker | AvosLocker has used XOR-encoded strings. |
| T1027 Obfuscated Files or Information |
MalwareCOATHANGER | COATHANGER can store obfuscated configuration information in the last 56 bytes of the file `/date/.bd.key/preload.so`. |
| T1027 Obfuscated Files or Information |
MalwareSardonic | Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string. |
| T1027 Obfuscated Files or Information |
MalwareMatryoshka | Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding. |
| T1027 Obfuscated Files or Information |
MalwareEcipekac | Ecipekac can use XOR, AES, and DES to encrypt loader shellcode. |
| T1027 Obfuscated Files or Information |
MalwareAppleSeed | AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027 Obfuscated Files or Information |
MalwareBUSHWALK | BUSHWALK can encrypt the resulting data generated from C2 commands with RC4. |
| T1027 Obfuscated Files or Information |
MalwareNETWIRE | NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1027 Obfuscated Files or Information |
MalwareBOOKWORM | BOOKWORM has been delivered using self-extracting RAR archives. |
| T1027 Obfuscated Files or Information |
MalwareOLDBAIT | OLDBAIT obfuscates internal strings and unpacks them at startup. |
| T1027 Obfuscated Files or Information |
MalwareTEARDROP | TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher. |
| T1027 Obfuscated Files or Information |
MalwareTurian | Turian can use VMProtect for obfuscation. |
| T1027 Obfuscated Files or Information |
MalwareAction RAT | Action RAT's commands, strings, and domains can be Base64 encoded within the payload. |
| T1027 Obfuscated Files or Information |
MalwarePUBLOAD | PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm. |
| T1027 Obfuscated Files or Information |
MalwareGootloader | The Gootloader first stage script is obfuscated using random alpha numeric strings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.