Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareAstaroth | Astaroth uses WMIC to execute payloads. |
| T1047 Windows Management Instrumentation |
MalwareQakBot | QakBot can execute WMI queries to gather information. |
| T1047 Windows Management Instrumentation |
MalwarejRAT | jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
| T1047 Windows Management Instrumentation |
MalwareINC Ransomware | INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment. |
| T1047 Windows Management Instrumentation |
MalwareFIVEHANDS | FIVEHANDS can use WMI to delete files on a target machine. |
| T1047 Windows Management Instrumentation |
MalwareHermeticWizard | HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`. |
| T1047 Windows Management Instrumentation |
ToolCovenant | Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners. |
| T1047 Windows Management Instrumentation |
ToolSILENTTRINITY | SILENTTRINITY can use WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
ToolPowerSploit | PowerSploit's |
| T1047 Windows Management Instrumentation |
ToolImpacket | Impacket's `wmiexec` module can be used to execute commands through WMI. |
| T1047 Windows Management Instrumentation |
ToolEmpire | Empire can use WMI to deliver a payload to a remote host. |
| T1047 Windows Management Instrumentation |
ToolPoshC2 | PoshC2 has a number of modules that use WMI to execute tasks. |
| T1047 Windows Management Instrumentation |
ToolBrute Ratel C4 | Brute Ratel C4 can use WMI to move laterally. |
| T1047 Windows Management Instrumentation |
ToolCrackMapExec | CrackMapExec can execute remote commands using Windows Management Instrumentation. |
| T1047 Windows Management Instrumentation |
ToolKoadic | Koadic can use WMI to execute commands. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareFrameworkPOS | FrameworkPOS can use DNS tunneling for exfiltration of credit card data. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareHydraq | Hydraq connects to a predefined domain on port 443 to exfil gathered information. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareChaes | Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareBundlore | Bundlore uses the |
| T1048 Exfiltration Over Alternative Protocol |
MalwareKobalos | Kobalos can exfiltrate credentials over the network via UDP. |
| T1048 Exfiltration Over Alternative Protocol |
MalwarePoetRAT | PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account. |
| T1048 Exfiltration Over Alternative Protocol |
ToolAADInternals | AADInternals can directly download cloud user data such as OneDrive files. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareIcedID | IcedID has exfiltrated collected data via HTTPS. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareBRUSHFIRE | BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
ToolRclone | Rclone can exfiltrate data over SFTP or HTTPS via WebDAV. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWindTail | WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareInvisibleFerret | InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareBrave Prince | Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCosmicDuke | CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePUBLOAD | PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareSocGholish | SocGholish can exfiltrate data directly to its C2 domain via HTTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareRemsec | Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCharmPower | CharmPower can send victim data via FTP with credentials hardcoded in the script. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKONNI | KONNI has used FTP to exfiltrate reconnaissance data out. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCORALDECK | CORALDECK has exfiltrated data in HTTP POST headers. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Malwareccf32 | ccf32 can upload collected data and files to an FTP server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWARPWIRE | WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCherry Picker | Cherry Picker exfiltrates files over FTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCarbon | Carbon uses HTTP to send data to the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKessel | Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePoetRAT | |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCookieMiner | CookieMiner has used the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareDok | Dok exfiltrates logs of its execution stored in the |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolRclone | Rclone can exfiltrate data over FTP or HTTP, including HTTP via WebDAV. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload files from a compromised host. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Toolftp | ftp may be used to exfiltrate data separate from the main command and control protocol. |
| T1049 System Network Connections Discovery |
MalwareTorisma | Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections. |
| T1049 System Network Connections Discovery |
MalwarePOWRUNER | POWRUNER may collect active network connections by running |
| T1049 System Network Connections Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.