Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1688 Safe Mode Boot |
MalwareEmbargo | Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode. |
| T1688 Safe Mode Boot |
MalwareBlack Basta | Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`. |
| T1688 Safe Mode Boot |
MalwareREvil | REvil can force a reboot in safe mode with networking. |
| T1688 Safe Mode Boot |
MalwareQilin | Qilin can reboot targeted systems in safe mode to avoid detection. |
| T1689 Downgrade Attack |
MalwareBlackByte Ransomware | BlackByte Ransomware enables SMBv1 during execution. |
| T1689 Downgrade Attack |
ToolSILENTTRINITY | SILENTTRINITY can downgrade NTLM to capture NTLM hashes. |
| T1690 Prevent Command History Logging |
MalwareBRICKSTORM | BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input. |
| T1690 Prevent Command History Logging |
MalwareLine Dancer | Line Dancer can disable syslog on compromised devices. |
| T1690 Prevent Command History Logging |
MalwareBPFDoor | BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
| T1690 Prevent Command History Logging |
MalwareVIRTUALPITA | VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service. |
| T1690 Prevent Command History Logging |
ToolSILENTTRINITY | SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.