Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1649 Steal or Forge Authentication Certificates |
ToolAADInternals | AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices. |
| T1649 Steal or Forge Authentication Certificates |
ToolMimikatz | Mimikatz's `CRYPTO` module can create and export various types of authentication certificates. |
| T1649 Steal or Forge Authentication Certificates |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments. |
| T1651 Cloud Administration Command |
ToolPacu | Pacu can run commands on EC2 instances using AWS Systems Manager Run Command. |
| T1651 Cloud Administration Command |
ToolAADInternals | AADInternals can execute commands on Azure virtual machines using the VM agent. |
| T1652 Device Driver Discovery |
MalwareHOPLIGHT | HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`. |
| T1652 Device Driver Discovery |
MalwareRemsec | Remsec has a plugin to detect active drivers of some security products. |
| T1652 Device Driver Discovery |
MalwareINC Ransomware | INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer. |
| T1653 Power Settings |
MalwareLine Dancer | Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes. |
| T1653 Power Settings |
MalwareLine Runner | Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload. |
| T1654 Log Enumeration |
MalwareDUSTTRAP | DUSTTRAP can identify infected system log information. |
| T1654 Log Enumeration |
MalwareMegazord | Megazord has the ability to print the trace, debug, error, info, and warning logs. |
| T1654 Log Enumeration |
MalwareBeaverTail | BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1654 Log Enumeration |
MalwareAkira _v2 | Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems. |
| T1654 Log Enumeration |
ToolPacu | Pacu can collect CloudTrail event histories and CloudWatch logs. |
| T1657 Financial Theft |
MalwareInvisibleFerret | InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025 |
| T1657 Financial Theft |
MalwareDarkGate | DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareGlassWorm | GlassWorm has the ability to steal credentials for cryptocurrency wallets. |
| T1657 Financial Theft |
MalwareEmbargo | Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom. |
| T1657 Financial Theft |
MalwareRedLine Stealer | RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers. |
| T1657 Financial Theft |
MalwareCrocodilus | Crocodilus has stolen cryptocurrency wallet details from victim devices. |
| T1657 Financial Theft |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero. |
| T1659 Content Injection |
MalwareDisco | Disco has achieved initial access and execution through content injection into DNS, HTTP, and SMB replies to targeted hosts that redirect them to download malicious files. |
| T1665 Hide Infrastructure |
MalwareJumbledPath | JumbledPath can use a chain of jump hosts to communicate with compromised devices to obscure actor infrastructure. |
| T1665 Hide Infrastructure |
MalwareUPSTYLE | UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages. |
| T1665 Hide Infrastructure |
MalwareDarkGate | DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services. |
| T1673 Virtual Machine Discovery |
MalwareCheerscrypt | Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them. |
| T1673 Virtual Machine Discovery |
MalwarePureCrypter | PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual. |
| T1673 Virtual Machine Discovery |
MalwareVIRTUALPITA | VIRTUALPITA can target specific guest virtual machines for script execution. |
| T1673 Virtual Machine Discovery |
MalwareQilin | Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments. |
| T1675 ESXi Administration Command |
MalwareVIRTUALPITA | VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors. |
| T1677 Poisoned Pipeline Execution |
MalwareShai-Hulud | Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`. |
| T1677 Poisoned Pipeline Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows. |
| T1677 Poisoned Pipeline Execution |
MalwareCanisterWorm | CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages. |
| T1678 Delay Execution |
MalwareBRICKSTORM | BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain. |
| T1678 Delay Execution |
MalwareTONESHELL | TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities. |
| T1678 Delay Execution |
MalwareDynoWiper | DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot. |
| T1678 Delay Execution |
MalwareSystemBC | SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds. |
| T1678 Delay Execution |
MalwareRustyWater | RustyWater has generated random sleep intervals between C2 communication. |
| T1678 Delay Execution |
MalwarePureCrypter | PureCrypter has the ability to delay for a specified number of seconds before execution. |
| T1678 Delay Execution |
MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
| T1678 Delay Execution |
MalwareFooder | Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
| T1678 Delay Execution |
MalwareGlassWorm | GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection. |
| T1678 Delay Execution |
MalwareAshTag | AshTag can use a set sleep time to delay C2 beaconing. |
| T1678 Delay Execution |
MalwarePHASEJAM | PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| T1678 Delay Execution |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution. |
| T1678 Delay Execution |
MalwareHIUPAN | HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available. |
| T1678 Delay Execution |
MalwareShai-Hulud | Shai-Hulud has delayed execution of its larger payloads by forking itself into background process. |
| T1678 Delay Execution |
MalwareQilin | Qilin has the ability to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.