Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1678 Delay Execution |
MalwareUPPERCUT | UPPERCUT can use a sleep function to delay execution. |
| T1678 Delay Execution |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution. |
| T1679 Selective Exclusion |
MalwareInvisibleFerret | InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types. |
| T1679 Selective Exclusion |
MalwareMedusa Ransomware | Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device. |
| T1679 Selective Exclusion |
MalwareDynoWiper | DynoWiper has recursively enumerated directories with the exception of the following: System32, Windows, Program Files, Program Files(x86), Temp, Recycle.Bin, $Recycle.Bin, Boot, PerfLogs, AppData, Documents and Settings. |
| T1679 Selective Exclusion |
MalwareSameCoin | SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf." |
| T1679 Selective Exclusion |
MalwareEmbargo | Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary. |
| T1679 Selective Exclusion |
MalwareLazyWiper | LazyWiper can enumerate the hostname of the system to determine if it is a domain controller and exclude it from being wiped if so. |
| T1680 Local Storage Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected disk information, including type and free space available. |
| T1680 Local Storage Discovery |
MalwareNinja | Ninja can obtain information on physical drives from targeted hosts. |
| T1680 Local Storage Discovery |
MalwareProxysvc | Proxysvc collects volume information for all drives on the system. |
| T1680 Local Storage Discovery |
MalwareTorisma | Torisma can use `GetlogicalDrives` to get a bitmask of all drives available on a compromised system. It can also use `GetDriveType` to determine if a new drive is a CD-ROM drive. |
| T1680 Local Storage Discovery |
MalwareNOKKI | NOKKI can gather information on drives on the victim’s machine. |
| T1680 Local Storage Discovery |
Malwareyty | yty gathers the the serial number of the main disk volume. |
| T1680 Local Storage Discovery |
MalwareKOPILUWAK | KOPILUWAK can discover logical drive information on compromised hosts. |
| T1680 Local Storage Discovery |
MalwareSardonic | Sardonic has the ability to collect the C:\ drive serial number from a compromised machine. |
| T1680 Local Storage Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect information on disk devices. |
| T1680 Local Storage Discovery |
MalwareBankshot | Bankshot gathers disk type and disk free space. |
| T1680 Local Storage Discovery |
MalwareSharpDisco | SharpDisco can use a plugin to enumerate system drives. |
| T1680 Local Storage Discovery |
MalwareStrongPity | StrongPity can identify the hard disk volume serial number on a compromised host. |
| T1680 Local Storage Discovery |
MalwareNebulae | Nebulae can discover logical drive information including the drive type, free space, and volume information. |
| T1680 Local Storage Discovery |
MalwareTONESHELL | TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine. |
| T1680 Local Storage Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has enumerated logical drives on infected hosts. |
| T1680 Local Storage Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner has checked to ensure there is enough disk space using the Unix utility `df`. |
| T1680 Local Storage Discovery |
MalwareAria-body | Aria-body has the ability to identify disk information on a compromised host. |
| T1680 Local Storage Discovery |
MalwareCrimson | Crimson contains a command to collect disk drive information. |
| T1680 Local Storage Discovery |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `GetLogicalDrives()` and `GetDriveType()` functions to enumerate all the drives visible to the system. |
| T1680 Local Storage Discovery |
MalwareAvenger | Avenger has the ability to identify the host volume ID. |
| T1680 Local Storage Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `wmic logicaldisk get` to map local network drives. |
| T1680 Local Storage Discovery |
MalwareWoody RAT | Woody RAT can retrieve information about storage drives from an infected machine. |
| T1680 Local Storage Discovery |
MalwareMafalda | Mafalda can enumerate all drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwareSUGARUSH | MoonWind can obtain the number of drives on the victim machine. |
| T1680 Local Storage Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed collecting victim machine volume information. |
| T1680 Local Storage Discovery |
MalwareInvisiMole | InvisiMole can gather information on the mapped drives and system volume serial number. |
| T1680 Local Storage Discovery |
MalwareWhisperGate | WhisperGate has the ability to enumerate fixed logical drives on a targeted system. |
| T1680 Local Storage Discovery |
MalwareBlackCat | BlackCat can enumerate local drives. |
| T1680 Local Storage Discovery |
MalwareNightdoor | Nightdoor can collect information about disk drives, their total and free space, and file system type. |
| T1680 Local Storage Discovery |
MalwareKazuar | Kazuar gathers information on local drives. |
| T1680 Local Storage Discovery |
MalwareRising Sun | Rising Sun can detect drive information, including drive type, total number of bytes on disk, total number of free bytes on disk, and name of a specified volume. |
| T1680 Local Storage Discovery |
MalwareChrommme | Chrommme has the ability to list drives. |
| T1680 Local Storage Discovery |
MalwareHELLOKITTY | HELLOKITTY can enumerate logical drives on a target system. |
| T1680 Local Storage Discovery |
MalwareCORESHELL | CORESHELL collects the volume serial number from the victim and sends the information to its C2 server. |
| T1680 Local Storage Discovery |
MalwareRunningRAT | RunningRAT gathers logical drives information and volume information. |
| T1680 Local Storage Discovery |
MalwareBabuk | Babuk can enumerate disk volumes, get disk information, and query service status. |
| T1680 Local Storage Discovery |
MalwareBlackMould | BlackMould can enumerate local drives on a compromised host. |
| T1680 Local Storage Discovery |
MalwarePlugX | PlugX has collected a list of all mapped drives on the infected host. |
| T1680 Local Storage Discovery |
MalwareReaver | Reaver collects volume serial number from the victim. |
| T1680 Local Storage Discovery |
MalwareEpic | Epic collects disk space information. |
| T1680 Local Storage Discovery |
MalwareCuba | Cuba can enumerate local drives, disk type, and disk free space. |
| T1680 Local Storage Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can enumerate logical drives on a target system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.