Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1620 Reflective Code Loading |
ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| T1620 Reflective Code Loading |
ToolDonut | Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
| T1621 Multi-Factor Authentication Request Generation |
CampaignC0027 | During C0027, Scattered Spider attempted to gain access by continuously sending MFA messages to the victim until they accept the MFA push challenge. |
| T1621 Multi-Factor Authentication Request Generation |
GroupScattered Spider | Scattered Spider has used multifactor authentication (MFA) fatigue by sending repeated MFA authentication requests to targets. |
| T1621 Multi-Factor Authentication Request Generation |
GroupAPT29 | APT29 has used repeated MFA requests to gain access to victim accounts. |
| T1621 Multi-Factor Authentication Request Generation |
GroupLAPSUS$ | LAPSUS$ has spammed target users with MFA prompts in the hope that the legitimate user will grant necessary approval. |
| T1622 Debugger Evasion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers. |
| T1622 Debugger Evasion |
GroupMustang Panda | Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1622 Debugger Evasion |
MalwarePikabot | Pikabot features several methods to evade debugging by analysts, including checks for active debuggers, the use of breakpoints during execution, and checking various system information items such as system memory and the number of processors. |
| T1622 Debugger Evasion |
MalwareBumblebee | Bumblebee can search for tools used in static analysis. |
| T1622 Debugger Evasion |
MalwareTONESHELL | TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger. |
| T1622 Debugger Evasion |
MalwarePUBLOAD | PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions. |
| T1622 Debugger Evasion |
MalwareMafalda | Mafalda can search for debugging tools on a compromised host. |
| T1622 Debugger Evasion |
MalwareRaspberry Robin | Raspberry Robin leverages anti-debugging mechanisms through the use of |
| T1622 Debugger Evasion |
MalwareRustyWater | RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts. |
| T1622 Debugger Evasion |
MalwareDRATzarus | DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim. |
| T1622 Debugger Evasion |
MalwareDarkTortilla | DarkTortilla can detect debuggers by using functions such as `DebuggerIsAttached` and `DebuggerIsLogging`. DarkTortilla can also detect profilers by verifying the `COR_ENABLE_PROFILING` environment variable is present and active. |
| T1622 Debugger Evasion |
MalwareROKRAT | ROKRAT can check for debugging tools. |
| T1622 Debugger Evasion |
MalwarePlugX | PlugX has made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1622 Debugger Evasion |
MalwareLumma Stealer | Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”. |
| T1622 Debugger Evasion |
MalwarePureCrypter | PureCrypter has the ability to call `CheckRemoteDebuggerPresent`. |
| T1622 Debugger Evasion |
MalwareDarkGate | DarkGate checks the |
| T1622 Debugger Evasion |
MalwareLockBit 3.0 | LockBit 3.0 can check heap memory parameters for indications of a debugger and stop the flow of events to the attached debugger in order to hinder dynamic analysis. |
| T1622 Debugger Evasion |
MalwareThiefQuest | ThiefQuest uses a function named |
| T1622 Debugger Evasion |
MalwareLatrodectus | Latrodectus has the ability to check for the presence of debuggers. |
| T1622 Debugger Evasion |
MalwareSaint Bot | Saint Bot has used `is_debugger_present` as part of its environmental checks. |
| T1622 Debugger Evasion |
MalwareBlack Basta | The Black Basta dropper can check system flags, CPU registers, CPU instructions, process timing, system libraries, and APIs to determine if a debugger is present. |
| T1622 Debugger Evasion |
MalwareStrelaStealer | StrelaStealer variants include functionality to identify and evade debuggers. |
| T1622 Debugger Evasion |
MalwareXLoader | XLoader uses anti-debugging mechanisms such as calling `NtQueryInformationProcess` with `InfoClass=7`, referencing `ProcessDebugPort`, to determine if it is being analyzed. |
| T1622 Debugger Evasion |
MalwareANELLDR | ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged. |
| T1622 Debugger Evasion |
MalwareStealBit | StealBit can detect it is being run in the context of a debugger. |
| T1622 Debugger Evasion |
ToolAsyncRAT | AsyncRAT can use the `CheckRemoteDebuggerPresent` function to detect the presence of a debugger. |
| T1647 Plist File Modification |
MalwareCuckoo Stealer | Cuckoo Stealer can create and populate property list (plist) files to enable execution. |
| T1647 Plist File Modification |
MalwareXCSSET | In older versions, XCSSET uses the |
| T1648 Serverless Execution |
ToolPacu | Pacu can create malicious Lambda functions. |
| T1649 Steal or Forge Authentication Certificates |
GroupAPT29 | APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates. |
| T1649 Steal or Forge Authentication Certificates |
ToolAADInternals | AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices. |
| T1649 Steal or Forge Authentication Certificates |
ToolMimikatz | Mimikatz's `CRYPTO` module can create and export various types of authentication certificates. |
| T1649 Steal or Forge Authentication Certificates |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments. |
| T1650 Acquire Access |
GroupMedusa Group | Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs). |
| T1651 Cloud Administration Command |
GroupAPT29 | APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines. |
| T1651 Cloud Administration Command |
GroupVOID MANTICORE | VOID MANTICORE has abused built-in remote wipe or factory reset commands to wipe devices managed within an organization’s Cloud management solution impacting laptops, servers, and mobile devices. |
| T1651 Cloud Administration Command |
ToolPacu | Pacu can run commands on EC2 instances using AWS Systems Manager Run Command. |
| T1651 Cloud Administration Command |
ToolAADInternals | AADInternals can execute commands on Azure virtual machines using the VM agent. |
| T1652 Device Driver Discovery |
GroupMedusa Group | Medusa Group has queried drivers on the victim device through the command `driverquery`. |
| T1652 Device Driver Discovery |
MalwareHOPLIGHT | HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`. |
| T1652 Device Driver Discovery |
MalwareRemsec | Remsec has a plugin to detect active drivers of some security products. |
| T1652 Device Driver Discovery |
MalwareINC Ransomware | INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer. |
| T1653 Power Settings |
CampaignArcaneDoor | ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant. |
| T1653 Power Settings |
MalwareLine Dancer | Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.