Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1049 System Network Connections Discovery |
ToolFRP | FRP can use a dashboard and U/I to display the status of connections from the FRP client and server. |
| T1049 System Network Connections Discovery |
Toolnetstat | netstat can be used to enumerate local network connections, including active TCP connections and other network statistics. |
| T1049 System Network Connections Discovery |
ToolPoshC2 | PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections. |
| T1049 System Network Connections Discovery |
Toolnbtstat | nbtstat can be used to discover current NetBIOS sessions. |
| T1049 System Network Connections Discovery |
ToolCrackMapExec | CrackMapExec can discover active sessions for a targeted system. |
| T1049 System Network Connections Discovery |
ToolPupy | Pupy has a built-in utility command for |
| T1049 System Network Connections Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1049 System Network Connections Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on network connections. |
| T1052.001 Exfiltration over USB |
MalwareMachete | Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| T1052.001 Exfiltration over USB |
MalwareAgent.btz | Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs. |
| T1052.001 Exfiltration over USB |
MalwareRemsec | Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| T1052.001 Exfiltration over USB |
MalwareSPACESHIP | SPACESHIP copies staged data to removable drives when they are inserted into the system. |
| T1052.001 Exfiltration over USB |
MalwareUSBStealer | USBStealer exfiltrates collected files via removable media from air-gapped victims. |
| T1053 Scheduled Task/Job |
MalwareLokibot | Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution. |
| T1053.002 At |
MalwareMURKYTOP | MURKYTOP has the capability to schedule remote AT jobs. |
| T1053.002 At |
Toolat | at can be used to schedule a task on a system to be executed at a specific date or time. |
| T1053.002 At |
ToolCrackMapExec | CrackMapExec can set a scheduled task on the target system to execute commands remotely using at. |
| T1053.003 Cron |
MalwareExaramel for Linux | Exaramel for Linux uses crontab for persistence if it does not have root privileges. |
| T1053.003 Cron |
MalwareJanicab | Janicab used a cron job for persistence on Mac devices. |
| T1053.003 Cron |
MalwareNETWIRE | NETWIRE can use crontabs to establish persistence. |
| T1053.003 Cron |
MalwareGomir | Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges. |
| T1053.003 Cron |
MalwareSkidmap | Skidmap has installed itself via crontab. |
| T1053.003 Cron |
MalwareGoldMax | The GoldMax Linux variant has used a crontab entry with a |
| T1053.003 Cron |
MalwareAnchor | Anchor can install itself as a cron job. |
| T1053.003 Cron |
MalwareXbash | Xbash can create a cronjob for persistence if it determines it is on a Linux system. |
| T1053.003 Cron |
MalwareSpeakUp | SpeakUp uses cron tasks to ensure persistence. |
| T1053.003 Cron |
MalwareNKAbuse | NKAbuse uses a Cron job to establish persistence when infecting Linux hosts. |
| T1053.003 Cron |
MalwarePenquin | Penquin can use Cron to create periodic and pre-scheduled background jobs. |
| T1053.003 Cron |
MalwareKinsing | Kinsing has used crontab to download and run shell scripts every minute to ensure persistence. |
| T1053.005 Scheduled Task |
MalwareTrickBot | TrickBot creates a scheduled task on the system that provides persistence. |
| T1053.005 Scheduled Task |
MalwareBumblebee | Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task. |
| T1053.005 Scheduled Task |
MalwareGRIFFON | GRIFFON has used |
| T1053.005 Scheduled Task |
Malwareyty | yty establishes persistence by creating a scheduled task with the command |
| T1053.005 Scheduled Task |
MalwareStuxnet | Stuxnet schedules a network job to execute two minutes after host infection. |
| T1053.005 Scheduled Task |
MalwarePOWRUNER | POWRUNER persists through a scheduled task that executes it every minute. |
| T1053.005 Scheduled Task |
MalwareSharpStage | SharpStage has a persistence component to write a scheduled task for the payload. |
| T1053.005 Scheduled Task |
MalwareSmoke Loader | Smoke Loader launches a scheduled task. |
| T1053.005 Scheduled Task |
MalwareMatryoshka | Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization". |
| T1053.005 Scheduled Task |
MalwareGravityRAT | GravityRAT creates a scheduled task to ensure it is re-executed everyday. |
| T1053.005 Scheduled Task |
MalwarePrestige | Prestige has been executed on a target system through a scheduled task created by Sandworm Team using Impacket. |
| T1053.005 Scheduled Task |
MalwareSharpDisco | SharpDisco can create scheduled tasks to execute reverse shells that read and write data to and from specified SMB shares. |
| T1053.005 Scheduled Task |
MalwareTONESHELL | TONESHELL has created scheduled tasks to maintain persistence. |
| T1053.005 Scheduled Task |
MalwareRainyDay | RainyDay can use scheduled tasks to achieve persistence. |
| T1053.005 Scheduled Task |
MalwareNETWIRE | NETWIRE can create a scheduled task to establish persistence. |
| T1053.005 Scheduled Task |
MalwareBad Rabbit | Bad Rabbit’s |
| T1053.005 Scheduled Task |
MalwareCosmicDuke | CosmicDuke uses scheduled tasks typically named "Watchmon Service" for persistence. |
| T1053.005 Scheduled Task |
MalwareIMAPLoader | IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine. |
| T1053.005 Scheduled Task |
MalwareEmotet | Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry. |
| T1053.005 Scheduled Task |
MalwareTomiris | Tomiris has used `SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00` to establish persistence. |
| T1053.005 Scheduled Task |
MalwareBADHATCH | BADHATCH can use `schtasks.exe` to gain persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.