Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
GroupEmber Bear | Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples. |
| T1505.003 Web Shell |
GroupVolatile Cedar | Volatile Cedar can inject web shell code into a server. |
| T1505.003 Web Shell |
GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| T1505.003 Web Shell |
GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| T1505.003 Web Shell |
GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| T1505.003 Web Shell |
GroupFox Kitten | Fox Kitten has installed web shells on compromised hosts to maintain access. |
| T1505.003 Web Shell |
GroupTonto Team | Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server. |
| T1505.003 Web Shell |
GroupMagic Hound | Magic Hound has used multiple web shells to gain execution. |
| T1505.003 Web Shell |
GroupThreat Group-3390 | Threat Group-3390 has used a variety of Web shells. |
| T1505.003 Web Shell |
GroupFIN13 | FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1518 Software Discovery |
GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1518 Software Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| T1518 Software Discovery |
GroupSidewinder | Sidewinder has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupMustang Panda | Mustang Panda has searched the victim system for the |
| T1518 Software Discovery |
GroupWindigo | Windigo has used a script to detect installed software on targeted systems. |
| T1518 Software Discovery |
GroupTropic Trooper | Tropic Trooper's backdoor could list the infected system's installed software. |
| T1518 Software Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupWindshift | Windshift has used malware to identify installed software. |
| T1518 Software Discovery |
GroupInception | Inception has enumerated installed software on compromised systems. |
| T1518 Software Discovery |
GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1518.001 Security Software Discovery |
GroupBlackByte | BlackByte enumerated installed security products during operations. |
| T1518.001 Security Software Discovery |
GroupSideCopy | SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1518.001 Security Software Discovery |
GroupPatchwork | Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool). |
| T1518.001 Security Software Discovery |
GroupMuddyWater | MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers. |
| T1518.001 Security Software Discovery |
GroupNaikon | Naikon uses commands such as |
| T1518.001 Security Software Discovery |
GroupGamaredon Group | Gamaredon Group has used PowerShell scripts to identify security software on the victim machine. |
| T1518.001 Security Software Discovery |
GroupTeamTNT | TeamTNT has searched for security products on infected machines. |
| T1518.001 Security Software Discovery |
GroupSidewinder | Sidewinder has used the Windows service |
| T1518.001 Security Software Discovery |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1518.001 Security Software Discovery |
GroupTA2541 | TA2541 has used tools to search victim systems for security products such as antivirus and firewall software. |
| T1518.001 Security Software Discovery |
GroupTropic Trooper | Tropic Trooper can search for anti-virus software running on the system. |
| T1518.001 Security Software Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| T1518.001 Security Software Discovery |
GroupThe White Company | The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET. |
| T1518.001 Security Software Discovery |
GroupTurla | Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected. |
| T1518.001 Security Software Discovery |
GroupStorm-0501 | Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`. |
| T1518.001 Security Software Discovery |
GroupMedusa Group | Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| T1518.001 Security Software Discovery |
GroupWindshift | Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
| T1518.001 Security Software Discovery |
GroupToddyCat | ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`. |
| T1518.001 Security Software Discovery |
GroupMalteiro | Malteiro collects the installed antivirus on the victim machine. |
| T1518.001 Security Software Discovery |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
GroupCobalt Group | Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine. |
| T1518.001 Security Software Discovery |
GroupWizard Spider | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine. |
| T1518.001 Security Software Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to scan for anti-virus software. |
| T1518.001 Security Software Discovery |
GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
| T1518.002 Backup Software Discovery |
GroupWizard Spider | Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.