Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
MalwarePysa | Pysa can perform network reconnaissance using the Advanced Port Scanner tool. |
| T1046 Network Service Discovery |
MalwareMgBot | MgBot includes modules for performing HTTP and server service scans. |
| T1046 Network Service Discovery |
MalwareSpeakUp | SpeakUp checks for availability of specific ports on servers. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1046 Network Service Discovery |
MalwareRamsay | Ramsay can scan for systems that are vulnerable to the EternalBlue exploit. |
| T1046 Network Service Discovery |
MalwareZxShell | ZxShell can launch port scans. |
| T1046 Network Service Discovery |
MalwareIndustroyer | Industroyer uses a custom port scanner to map out a network. |
| T1046 Network Service Discovery |
MalwareHermeticWizard | HermeticWizard has the ability to scan ports on a compromised network. |
| T1046 Network Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can scan for open ports on a compromised machine. |
| T1046 Network Service Discovery |
ToolEmpire | Empire can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolFRP | As part of load balancing FRP can set `healthCheck.type = "tcp"` or `healthCheck.type = "http"` to check service status on specific hosts with TCPing or an HTTP request. |
| T1046 Network Service Discovery |
ToolPoshC2 | PoshC2 can perform port scans from an infected host. |
| T1046 Network Service Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can conduct port scanning against targeted systems. |
| T1046 Network Service Discovery |
ToolPeirates | Peirates can initiate a port scan against a given IP address. |
| T1046 Network Service Discovery |
ToolNBTscan | NBTscan can be used to scan IP networks. |
| T1046 Network Service Discovery |
ToolKoadic | Koadic can scan for open TCP ports on the target network. |
| T1046 Network Service Discovery |
ToolPupy | Pupy has a built-in module for port scanning. |
| T1047 Windows Management Instrumentation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1047 Windows Management Instrumentation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used WMI for execution. |
| T1047 Windows Management Instrumentation |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version. |
| T1047 Windows Management Instrumentation |
CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| T1047 Windows Management Instrumentation |
CampaignC0015 | During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| T1047 Windows Management Instrumentation |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| T1047 Windows Management Instrumentation |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1047 Windows Management Instrumentation |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
| T1047 Windows Management Instrumentation |
CampaignFunnyDream | During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| T1047 Windows Management Instrumentation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| T1047 Windows Management Instrumentation |
CampaignOperation Wocao | During Operation Wocao, threat actors has used WMI to execute commands. |
| T1047 Windows Management Instrumentation |
CampaignC0027 | During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
| T1047 Windows Management Instrumentation |
GroupIndrik Spider | Indrik Spider has used WMIC to execute commands on remote computers. |
| T1047 Windows Management Instrumentation |
GroupBlackByte | BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| T1047 Windows Management Instrumentation |
GroupGALLIUM | GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1047 Windows Management Instrumentation |
GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| T1047 Windows Management Instrumentation |
GroupmenuPass | menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
| T1047 Windows Management Instrumentation |
GroupAPT32 | APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1047 Windows Management Instrumentation |
GroupNaikon | Naikon has used WMIC.exe for lateral movement. |
| T1047 Windows Management Instrumentation |
GroupFIN6 | FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1047 Windows Management Instrumentation |
GroupGamaredon Group | Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`. |
| T1047 Windows Management Instrumentation |
GroupFIN7 | FIN7 has used WMI to install malware on targeted systems. |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1047 Windows Management Instrumentation |
GroupMustang Panda | Mustang Panda has executed PowerShell scripts via WMI. |
| T1047 Windows Management Instrumentation |
GroupTA2541 | TA2541 has used WMI to query targeted systems for security products. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| T1047 Windows Management Instrumentation |
GroupLeviathan | Leviathan has used WMI for execution. |
| T1047 Windows Management Instrumentation |
GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe to set environment variables. |
| T1047 Windows Management Instrumentation |
GroupLotus Blossom | Lotus Blossom has used WMI to enable lateral movement. |
| T1047 Windows Management Instrumentation |
GroupStealth Falcon | Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.