Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
MalwareXbash | Xbash can perform port scanning of TCP and UDP ports. |
| T1046 Network Service Discovery |
MalwareXTunnel | XTunnel is capable of probing the network for open ports. |
| T1046 Network Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a port scanner on a system. |
| T1046 Network Service Discovery |
MalwareRoyal | Royal can scan the network interfaces of targeted systems. |
| T1046 Network Service Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads. |
| T1046 Network Service Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced Port Scanner tool. |
| T1046 Network Service Discovery |
MalwareMgBot | MgBot includes modules for performing HTTP and server service scans. |
| T1046 Network Service Discovery |
MalwareSpeakUp | SpeakUp checks for availability of specific ports on servers. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1046 Network Service Discovery |
MalwareRamsay | Ramsay can scan for systems that are vulnerable to the EternalBlue exploit. |
| T1046 Network Service Discovery |
MalwareZxShell | ZxShell can launch port scans. |
| T1046 Network Service Discovery |
MalwareIndustroyer | Industroyer uses a custom port scanner to map out a network. |
| T1046 Network Service Discovery |
MalwareHermeticWizard | HermeticWizard has the ability to scan ports on a compromised network. |
| T1046 Network Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can scan for open ports on a compromised machine. |
| T1046 Network Service Discovery |
ToolEmpire | Empire can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolFRP | As part of load balancing FRP can set `healthCheck.type = "tcp"` or `healthCheck.type = "http"` to check service status on specific hosts with TCPing or an HTTP request. |
| T1046 Network Service Discovery |
ToolPoshC2 | PoshC2 can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can conduct port scanning against targeted systems. |
| T1046 Network Service Discovery |
ToolPeirates | Peirates can initiate a port scan against a given IP address. |
| T1046 Network Service Discovery |
ToolNBTscan | NBTscan can be used to scan IP networks. |
| T1046 Network Service Discovery |
ToolKoadic | Koadic can scan for open TCP ports on the target network. |
| T1046 Network Service Discovery |
ToolPupy | Pupy has a built-in module for port scanning. |
| T1047 Windows Management Instrumentation |
MalwareEKANS | EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1047 Windows Management Instrumentation |
MalwareStuxnet | Stuxnet used WMI with an |
| T1047 Windows Management Instrumentation |
MalwarePOWRUNER | POWRUNER may use WMI when collecting information about a victim. |
| T1047 Windows Management Instrumentation |
MalwareSharpStage | SharpStage can use WMI for execution. |
| T1047 Windows Management Instrumentation |
MalwareSardonic | Sardonic can use WMI to execute PowerShell commands on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareHALFBAKED | HALFBAKED can use WMI queries to gather system information. |
| T1047 Windows Management Instrumentation |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
MalwareUrsnif | Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1047 Windows Management Instrumentation |
MalwareGravityRAT | GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed). |
| T1047 Windows Management Instrumentation |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1047 Windows Management Instrumentation |
MalwareTONESHELL | TONESHELL has used WMI queries to gather information from the system. |
| T1047 Windows Management Instrumentation |
MalwarePyDCrypt | PyDCrypt has attempted to execute with WMIC. |
| T1047 Windows Management Instrumentation |
MalwareIMAPLoader | IMAPLoader uses WMI queries to query system information on victim hosts. |
| T1047 Windows Management Instrumentation |
MalwareEmotet | Emotet has used WMI to execute powershell.exe. |
| T1047 Windows Management Instrumentation |
MalwareOlympic Destroyer | Olympic Destroyer uses WMI to help propagate itself across a network. |
| T1047 Windows Management Instrumentation |
MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareAction RAT | Action RAT can use WMI to gather AV products installed on an infected host. |
| T1047 Windows Management Instrumentation |
MalwarePUBLOAD | PUBLOAD has used `wmic` to gather information from the victim device. |
| T1047 Windows Management Instrumentation |
MalwareShrinkLocker | ShrinkLocker uses WMI to query information about the victim operating system. |
| T1047 Windows Management Instrumentation |
MalwareFlawedAmmyy | FlawedAmmyy leverages WMI to enumerate anti-virus on the victim. |
| T1047 Windows Management Instrumentation |
MalwareSnip3 | Snip3 can query the WMI class `Win32_ComputerSystem` to gather information. |
| T1047 Windows Management Instrumentation |
MalwareHOPLIGHT | HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository. |
| T1047 Windows Management Instrumentation |
MalwareProLock | ProLock can use WMIC to execute scripts on targeted hosts. |
| T1047 Windows Management Instrumentation |
MalwareRaspberry Robin | Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package. |
| T1047 Windows Management Instrumentation |
MalwareBlackCat | BlackCat can use `wmic.exe` to delete shadow copies on compromised networks. |
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1047 Windows Management Instrumentation |
MalwareKazuar | Kazuar obtains a list of running processes through WMI querying. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.