Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1119 Automated Collection |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1119 Automated Collection |
GroupRedCurl | RedCurl has used batch scripts to collect data. |
| T1119 Automated Collection |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1119 Automated Collection |
GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| T1119 Automated Collection |
GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| T1119 Automated Collection |
GroupAgrius | Agrius used a custom tool, |
| T1119 Automated Collection |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1119 Automated Collection |
GroupVOID MANTICORE | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems. |
| T1119 Automated Collection |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1120 Peripheral Device Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained victim's screen dimension and display device information. |
| T1120 Peripheral Device Discovery |
GroupGamaredon Group | Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives. |
| T1120 Peripheral Device Discovery |
GroupTeamTNT | TeamTNT has searched for attached VGA devices using lspci. |
| T1120 Peripheral Device Discovery |
GroupAPT37 | APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices. |
| T1120 Peripheral Device Discovery |
GroupOilRig | OilRig has used tools to identify if a mouse is connected to a targeted system. |
| T1120 Peripheral Device Discovery |
GroupTurla | Turla has used |
| T1120 Peripheral Device Discovery |
GroupEquation | Equation has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware. |
| T1120 Peripheral Device Discovery |
GroupBackdoorDiplomacy | BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives. |
| T1120 Peripheral Device Discovery |
GroupAPT28 | APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. |
| T1123 Audio Capture |
GroupAPT37 | APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input. |
| T1123 Audio Capture |
GroupVOID MANTICORE | VOID MANTICORE has gathered audio during a Zoom session. |
| T1124 System Time Discovery |
GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| T1124 System Time Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system timezone. |
| T1124 System Time Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| T1124 System Time Discovery |
GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| T1124 System Time Discovery |
GroupSidewinder | Sidewinder has used tools to obtain the current system time. |
| T1124 System Time Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
| T1124 System Time Discovery |
GroupUNC3886 | UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts. |
| T1124 System Time Discovery |
GroupHigaisa | Higaisa used a function to gather the current time. |
| T1124 System Time Discovery |
GroupThe White Company | The White Company has checked the current date on the victim system. |
| T1124 System Time Discovery |
GroupTurla | Turla surveys a system upon check-in to discover the system time by using the |
| T1124 System Time Discovery |
GroupChimera | Chimera has used |
| T1124 System Time Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1124 System Time Discovery |
GroupDarkhotel | Darkhotel malware can obtain system time from a compromised host. |
| T1124 System Time Discovery |
GroupLazarus Group | A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server. |
| T1125 Video Capture |
GroupFIN7 | FIN7 created a custom video recording capability that could be used to monitor operations in the victim's environment. |
| T1125 Video Capture |
GroupEmber Bear | Ember Bear has exfiltrated images from compromised IP cameras. |
| T1125 Video Capture |
GroupSilence | Silence has been observed making videos of victims to observe bank employees day to day activities. |
| T1125 Video Capture |
GroupVOID MANTICORE | VOID MANTICORE has collected video from compromised victim devices. |
| T1129 Shared Modules |
GroupMustang Panda | Mustang Panda has leveraged `LoadLibrary` to load DLLs. |
| T1132 Data Encoding |
GroupVelvet Ant | Velvet Ant sent commands to compromised F5 BIG-IP devices in an encoded format requiring a passkey before interpretation and execution. |
| T1132.001 Standard Encoding |
GroupPatchwork | Patchwork used Base64 to encode C2 traffic. |
| T1132.001 Standard Encoding |
GroupHAFNIUM | HAFNIUM has used ASCII encoding for C2 traffic. |
| T1132.001 Standard Encoding |
GroupMuddyWater | MuddyWater has used tools to encode C2 communications including Base64 encoding. |
| T1132.001 Standard Encoding |
GroupSandworm Team | Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server. |
| T1132.001 Standard Encoding |
GroupTropic Trooper | Tropic Trooper has used base64 encoding to hide command strings delivered from the C2. |
| T1132.001 Standard Encoding |
GroupBRONZE BUTLER | Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server. |
| T1132.001 Standard Encoding |
GroupTA551 | TA551 has used encoded ASCII text for initial C2 communications. |
| T1132.001 Standard Encoding |
GroupAPT42 | APT42 has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
GroupLazarus Group | A Lazarus Group malware sample encodes data with base64. |
| T1132.001 Standard Encoding |
GroupAPT33 | APT33 has used base64 to encode command and control traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.