Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1120 Peripheral Device Discovery |
MalwareBADNEWS | BADNEWS checks for new hard drives on the victim, such as USB devices, by listening for the WM_DEVICECHANGE window message. |
| T1120 Peripheral Device Discovery |
MalwareQakBot | QakBot can identify peripheral devices on targeted systems. |
| T1120 Peripheral Device Discovery |
MalwarejRAT | jRAT can map UPnP ports. |
| T1120 Peripheral Device Discovery |
MalwareINC Ransomware | INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes. |
| T1120 Peripheral Device Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list connected devices. |
| T1123 Audio Capture |
GroupAPT37 | APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input. |
| T1123 Audio Capture |
GroupVOID MANTICORE | VOID MANTICORE has gathered audio during a Zoom session. |
| T1123 Audio Capture |
MalwareDOGCALL | DOGCALL can capture microphone data from the victim's machine. |
| T1123 Audio Capture |
MalwareJanicab | Janicab captured audio and sent it out to a C2 server. |
| T1123 Audio Capture |
MalwareEvilGrab | EvilGrab has the capability to capture audio from a victim machine. |
| T1123 Audio Capture |
MalwareCrimson | Crimson can perform audio surveillance using microphones. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1123 Audio Capture |
MalwareInvisiMole | InvisiMole can record sound using input audio devices. |
| T1123 Audio Capture |
MalwareVERMIN | VERMIN can perform audio capture. |
| T1123 Audio Capture |
MalwareDarkComet | DarkComet can listen in to victims' conversations through the system’s microphone. |
| T1123 Audio Capture |
MalwareLightSpy | LightSpy uses Apple's built-in AVFoundation Framework library to capture and manage audio recordings then transform them to JSON blobs for exfiltration. |
| T1123 Audio Capture |
MalwareROKRAT | ROKRAT has an audio capture and eavesdropping module. |
| T1123 Audio Capture |
MalwareBandook | Bandook has modules that are capable of capturing audio. |
| T1123 Audio Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1123 Audio Capture |
MalwareMicropsia | Micropsia can perform microphone recording. |
| T1123 Audio Capture |
MalwareAttor | Attor's has a plugin that is capable of recording audio using available input sound devices. |
| T1123 Audio Capture |
MalwareNightClub | NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio. |
| T1123 Audio Capture |
MalwareDerusbi | Derusbi is capable of performing audio captures. |
| T1123 Audio Capture |
MalwareMgBot | MgBot can capture input and output audio streams from infected devices. |
| T1123 Audio Capture |
MalwareCadelspy | Cadelspy has the ability to record audio from the compromised host. |
| T1123 Audio Capture |
MalwareCobian RAT | Cobian RAT has a feature to perform voice recording on the victim’s machine. |
| T1123 Audio Capture |
MalwareNanoCore | NanoCore can capture audio feeds from the system. |
| T1123 Audio Capture |
MalwareTajMahal | TajMahal has the ability to capture VoiceIP application audio on an infected host. |
| T1123 Audio Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for microphone interception. |
| T1123 Audio Capture |
MalwareMacMa | MacMa has the ability to record audio. |
| T1123 Audio Capture |
MalwarejRAT | jRAT can capture microphone recordings. |
| T1123 Audio Capture |
MalwareMacSpy | MacSpy can record the sounds from microphones on a computer. |
| T1123 Audio Capture |
ToolPowerSploit | PowerSploit's |
| T1123 Audio Capture |
ToolRemcos | Remcos can capture data from the system’s microphone. |
| T1123 Audio Capture |
ToolImminent Monitor | Imminent Monitor has a remote microphone monitoring capability. |
| T1123 Audio Capture |
ToolPupy | Pupy can record sound with the microphone. |
| T1123 Audio Capture |
MalwareFlame | Flame can record audio using any existing hardware recording devices. |
| T1124 System Time Discovery |
CampaignC0015 | During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network. |
| T1124 System Time Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net time` command as part of their advanced reconnaissance. |
| T1124 System Time Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `time` command to retrieve the current time of a compromised system. |
| T1124 System Time Discovery |
GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| T1124 System Time Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system timezone. |
| T1124 System Time Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| T1124 System Time Discovery |
GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| T1124 System Time Discovery |
GroupSidewinder | Sidewinder has used tools to obtain the current system time. |
| T1124 System Time Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
| T1124 System Time Discovery |
GroupUNC3886 | UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts. |
| T1124 System Time Discovery |
GroupHigaisa | Higaisa used a function to gather the current time. |
| T1124 System Time Discovery |
GroupThe White Company | The White Company has checked the current date on the victim system. |
| T1124 System Time Discovery |
GroupTurla | Turla surveys a system upon check-in to discover the system time by using the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.