Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1029 Scheduled Transfer |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure. |
| T1029 Scheduled Transfer |
MalwareShadowPad | ShadowPad has sent data back to C2 every 8 hours. |
| T1029 Scheduled Transfer |
MalwarejRAT | jRAT can be configured to reconnect at certain intervals. |
| T1029 Scheduled Transfer |
MalwareADVSTORESHELL | ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
| T1030 Data Transfer Size Limits |
MalwareAppleSeed | AppleSeed has divided files if the size is 0x1000000 bytes or more. |
| T1030 Data Transfer Size Limits |
MalwareRDAT | RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions. |
| T1030 Data Transfer Size Limits |
MalwareObliqueRAT | ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration. |
| T1030 Data Transfer Size Limits |
MalwarePOSHSPY | POSHSPY uploads data in 2048-byte chunks. |
| T1030 Data Transfer Size Limits |
MalwareCarbanak | Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes . |
| T1030 Data Transfer Size Limits |
MalwareOopsIE | OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks. |
| T1030 Data Transfer Size Limits |
MalwareCobalt Strike | Cobalt Strike will break large data sets into smaller chunks for exfiltration. |
| T1030 Data Transfer Size Limits |
MalwareKessel | Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries. |
| T1030 Data Transfer Size Limits |
MalwareStealBit | StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms. |
| T1030 Data Transfer Size Limits |
MalwareLunarWeb | LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB. |
| T1030 Data Transfer Size Limits |
MalwareKevin | Kevin can exfiltrate data to the C2 server in 27-character chunks. |
| T1030 Data Transfer Size Limits |
MalwareHelminth | Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server. |
| T1030 Data Transfer Size Limits |
ToolRclone | The Rclone "chunker" overlay supports splitting large files in smaller chunks during upload to circumvent size limits. |
| T1030 Data Transfer Size Limits |
ToolMythic | Mythic supports custom chunk sizes used to upload/download files. |
| T1033 System Owner/User Discovery |
MalwareTrickBot | TrickBot can identify the user and groups the user belongs to on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarePowerDuke | PowerDuke has commands to get the current user's name and SID. |
| T1033 System Owner/User Discovery |
MalwareRCSession | RCSession can gather system owner information, including user and administrator privileges. |
| T1033 System Owner/User Discovery |
MalwareSpark | Spark has run the whoami command and has a built-in command to identify the user logged in. |
| T1033 System Owner/User Discovery |
MalwareSynAck | SynAck gathers user names from infected hosts. |
| T1033 System Owner/User Discovery |
MalwareBumblebee | Bumblebee has the ability to identify the user name. |
| T1033 System Owner/User Discovery |
MalwareAmadey | Amadey has collected the user name from a compromised host using `GetUserNameA`. |
| T1033 System Owner/User Discovery |
MalwareNOKKI | NOKKI can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
Malwareyty | yty collects the victim’s username. |
| T1033 System Owner/User Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects the current username from the victim. |
| T1033 System Owner/User Discovery |
MalwareIronWind | IronWind can enumerate the username on victim's systems. |
| T1033 System Owner/User Discovery |
MalwareGet2 | Get2 has the ability to identify the current username of an infected host. |
| T1033 System Owner/User Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the currently logged in user by running |
| T1033 System Owner/User Discovery |
MalwareKOPILUWAK | KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details. |
| T1033 System Owner/User Discovery |
MalwareLinux Rabbit | Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain. |
| T1033 System Owner/User Discovery |
MalwareExaramel for Linux | Exaramel for Linux can run |
| T1033 System Owner/User Discovery |
MalwareHAWKBALL | HAWKBALL can collect the user name of the system. |
| T1033 System Owner/User Discovery |
MalwareRedLeaves | RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions. |
| T1033 System Owner/User Discovery |
MalwareFelismus | Felismus collects the current username and sends it to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareHavoc | Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1033 System Owner/User Discovery |
MalwareGravityRAT | GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status). |
| T1033 System Owner/User Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified the user’s UUID and username through the "pay" module. |
| T1033 System Owner/User Discovery |
MalwareHAPPYWORK | can collect the victim user name. |
| T1033 System Owner/User Discovery |
MalwareWinMM | WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system. |
| T1033 System Owner/User Discovery |
MalwareTONESHELL | TONESHELL has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwarePyDCrypt | PyDCrypt has probed victim machines with |
| T1033 System Owner/User Discovery |
MalwareBOOKWORM | BOOKWORM has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareSslMM | SslMM sends the logged-on username to its hard-coded C2. |
| T1033 System Owner/User Discovery |
MalwareAria-body | Aria-body has the ability to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareEmotet | Emotet has enumerated all users connected to network shares. |
| T1033 System Owner/User Discovery |
MalwareCrimson | Crimson can identify the user on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareTurian | Turian can retrieve usernames. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.