Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1686.003 Windows Host Firewall |
GroupOilRig | OilRig has modified Windows firewall rules to enable remote access. |
| T1686.003 Windows Host Firewall |
GroupMirrorFace | MirrorFace can modify the system firewall to allow communication to certain ports. |
| T1686.003 Windows Host Firewall |
GroupLazarus Group | Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh. |
| T1686.003 Windows Host Firewall |
GroupVOID MANTICORE | VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host. |
| T1686.003 Windows Host Firewall |
GroupMagic Hound | Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`. |
| T1686.003 Windows Host Firewall |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the Windows firewall during execution. |
| T1686.003 Windows Host Firewall |
MalwareDarkComet | DarkComet can disable Security Center functions like the Windows Firewall. |
| T1686.003 Windows Host Firewall |
MalwareRemsec | Remsec can add or remove applications or ports on the Windows firewall or disable it entirely. |
| T1686.003 Windows Host Firewall |
MalwareTYPEFRAME | TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections. |
| T1686.003 Windows Host Firewall |
MalwareBADCALL | BADCALL disables the Windows firewall before binding to a port. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
| T1686.003 Windows Host Firewall |
MalwareHARDRAIN | HARDRAIN opens the Windows Firewall to modify incoming connections. |
| T1686.003 Windows Host Firewall |
MalwarenjRAT | njRAT has modified the Windows firewall to allow itself to communicate through the firewall. |
| T1686.003 Windows Host Firewall |
MalwareH1N1 | H1N1 kills and disables services for Windows Firewall. |
| T1688 Safe Mode Boot |
MalwareAvosLocker | AvosLocker can restart a compromised machine in safe mode. |
| T1688 Safe Mode Boot |
MalwareRansomHub | RansomHub can reboot targeted systems into Safe Mode prior to encryption. |
| T1688 Safe Mode Boot |
MalwareLockBit 3.0 | LockBit 3.0 can reboot the infected host into Safe Mode. |
| T1688 Safe Mode Boot |
MalwareEmbargo | Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode. |
| T1688 Safe Mode Boot |
MalwareBlack Basta | Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`. |
| T1688 Safe Mode Boot |
MalwareREvil | REvil can force a reboot in safe mode with networking. |
| T1688 Safe Mode Boot |
MalwareQilin | Qilin can reboot targeted systems in safe mode to avoid detection. |
| T1689 Downgrade Attack |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment. |
| T1689 Downgrade Attack |
MalwareBlackByte Ransomware | BlackByte Ransomware enables SMBv1 during execution. |
| T1689 Downgrade Attack |
ToolSILENTTRINITY | SILENTTRINITY can downgrade NTLM to capture NTLM hashes. |
| T1690 Prevent Command History Logging |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging. |
| T1690 Prevent Command History Logging |
CampaignArcaneDoor | ArcaneDoor included disabling logging on targeted Cisco ASA appliances. |
| T1690 Prevent Command History Logging |
GroupAPT38 | APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment. |
| T1690 Prevent Command History Logging |
GroupUNC3886 | UNC3886 has tampered with and disabled logging services on targeted systems. |
| T1690 Prevent Command History Logging |
GroupSea Turtle | Sea Turtle unset the Bash and MySQL history files on victim systems. |
| T1690 Prevent Command History Logging |
GroupMedusa Group | Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`. |
| T1690 Prevent Command History Logging |
MalwareBRICKSTORM | BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input. |
| T1690 Prevent Command History Logging |
MalwareLine Dancer | Line Dancer can disable syslog on compromised devices. |
| T1690 Prevent Command History Logging |
MalwareBPFDoor | BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
| T1690 Prevent Command History Logging |
MalwareVIRTUALPITA | VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service. |
| T1690 Prevent Command History Logging |
ToolSILENTTRINITY | SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.