Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685.005 Clear Windows Event Logs |
MalwareNotPetya | NotPetya uses |
| T1685.005 Clear Windows Event Logs |
MalwareRunningRAT | RunningRAT contains code to clear event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareMultiLayer Wiper | MultiLayer Wiper removes Windows event logs during execution. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 3.0 | LockBit 3.0 can delete log files on targeted systems. |
| T1685.005 Clear Windows Event Logs |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can clear all system event logs. |
| T1685.005 Clear Windows Event Logs |
Malwaregh0st RAT | gh0st RAT is able to wipe event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWiper | HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 2.0 | LockBit 2.0 can delete log files through the use of wevtutil. |
| T1685.005 Clear Windows Event Logs |
MalwareFinFisher | FinFisher clears the system event logs using |
| T1685.005 Clear Windows Event Logs |
MalwareZxShell | ZxShell has a command to clear system event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareMeteor | Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs. |
| T1685.005 Clear Windows Event Logs |
MalwareKillDisk | KillDisk deletes Application, Security, Setup, and System Windows Event Logs. |
| T1685.005 Clear Windows Event Logs |
MalwareQilin | Qilin has the ability to clear Windows Event Logs. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWizard | HermeticWizard has the ability to use `wevtutil cl system` to clear event logs. |
| T1685.005 Clear Windows Event Logs |
ToolPupy | Pupy has a module to clear event logs with PowerShell. |
| T1685.005 Clear Windows Event Logs |
ToolWevtutil | Wevtutil can be used to clear system and security event logs from the system. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareJumbledPath | JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareUPSTYLE | UPSTYLE clears error logs after reading embedded commands for execution. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareMacMa | MacMa can clear possible malware traces such as application logs. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareProton | Proton removes logs from |
| T1686 Disable or Modify System Firewall |
MalwareKasidet | Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded. |
| T1686 Disable or Modify System Firewall |
MalwareHannotog | Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
| T1686 Disable or Modify System Firewall |
MalwarePyDCrypt | PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines. |
| T1686 Disable or Modify System Firewall |
MalwareTHINCRUST | THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
| T1686 Disable or Modify System Firewall |
MalwareHOPLIGHT | |
| T1686 Disable or Modify System Firewall |
MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
| T1686 Disable or Modify System Firewall |
MalwarePlugX | PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity. |
| T1686 Disable or Modify System Firewall |
MalwareBPFDoor | BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port. |
| T1686 Disable or Modify System Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686 Disable or Modify System Firewall |
MalwareNanoCore | NanoCore can modify the victim's firewall. |
| T1686 Disable or Modify System Firewall |
MalwareZxShell | ZxShell can disable the firewall by modifying the registry key |
| T1686 Disable or Modify System Firewall |
MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| T1686 Disable or Modify System Firewall |
MalwareBACKSPACE | The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed. |
| T1686 Disable or Modify System Firewall |
Toolnetsh | netsh can be used to disable local firewall settings. |
| T1686.001 Cloud Firewall |
ToolPacu | Pacu can allowlist IP addresses in AWS GuardDuty. |
| T1686.002 Network Device Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686.002 Network Device Firewall |
MalwareCyclops Blink | Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers. |
| T1686.003 Windows Host Firewall |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the Windows firewall during execution. |
| T1686.003 Windows Host Firewall |
MalwareDarkComet | DarkComet can disable Security Center functions like the Windows Firewall. |
| T1686.003 Windows Host Firewall |
MalwareRemsec | Remsec can add or remove applications or ports on the Windows firewall or disable it entirely. |
| T1686.003 Windows Host Firewall |
MalwareTYPEFRAME | TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections. |
| T1686.003 Windows Host Firewall |
MalwareBADCALL | BADCALL disables the Windows firewall before binding to a port. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
| T1686.003 Windows Host Firewall |
MalwareHARDRAIN | HARDRAIN opens the Windows Firewall to modify incoming connections. |
| T1686.003 Windows Host Firewall |
MalwarenjRAT | njRAT has modified the Windows firewall to allow itself to communicate through the firewall. |
| T1686.003 Windows Host Firewall |
MalwareH1N1 | H1N1 kills and disables services for Windows Firewall. |
| T1688 Safe Mode Boot |
MalwareAvosLocker | AvosLocker can restart a compromised machine in safe mode. |
| T1688 Safe Mode Boot |
MalwareRansomHub | RansomHub can reboot targeted systems into Safe Mode prior to encryption. |
| T1688 Safe Mode Boot |
MalwareLockBit 3.0 | LockBit 3.0 can reboot the infected host into Safe Mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.