Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1069.002 Domain Groups |
MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| T1069.002 Domain Groups |
MalwareREvil | REvil can identify the domain membership of a compromised host. |
| T1069.002 Domain Groups |
MalwareKwampirs | Kwampirs collects a list of domain groups with the command |
| T1069.002 Domain Groups |
MalwareLAMEHUG | |
| T1069.002 Domain Groups |
MalwareEgregor | Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1069.002 Domain Groups |
MalwareQilin | Qilin can run PowerShell cmdlets to discover domain groups. |
| T1069.002 Domain Groups |
MalwareSoreFang | SoreFang can enumerate domain groups by executing |
| T1069.002 Domain Groups |
MalwareHelminth | Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands |
| T1069.002 Domain Groups |
MalwareOSInfo | OSInfo specifically looks for Domain Admins and power users within the domain. |
| T1069.002 Domain Groups |
ToolNet | Commands such as |
| T1069.002 Domain Groups |
ToolBloodHound | BloodHound can collect information about domain groups and members. |
| T1069.002 Domain Groups |
ToolSILENTTRINITY | SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information. |
| T1069.002 Domain Groups |
Tooldsquery | dsquery can be used to gather information on permission groups within a domain. |
| T1069.002 Domain Groups |
ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1069.002 Domain Groups |
ToolCrackMapExec | CrackMapExec can gather the user accounts within domain groups. |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
| T1069.003 Cloud Groups |
ToolPacu | Pacu can enumerate IAM permissions. |
| T1069.003 Cloud Groups |
ToolAADInternals | AADInternals can enumerate Azure AD groups. |
| T1069.003 Cloud Groups |
ToolROADTools | ROADTools can enumerate Azure AD groups. |
| T1070 Indicator Removal |
MalwareOrz | Orz can overwrite Registry settings to reduce its visibility on the victim. |
| T1070 Indicator Removal |
MalwareStuxnet | Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads. |
| T1070 Indicator Removal |
MalwareIronWind | IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems. |
| T1070 Indicator Removal |
MalwareSardonic | Sardonic has the ability to delete created WMI objects to evade detections. |
| T1070 Indicator Removal |
MalwareBankshot | Bankshot deletes all artifacts associated with the malware from the infected machine. |
| T1070 Indicator Removal |
MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070 Indicator Removal |
MalwareNeoichor | Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key. |
| T1070 Indicator Removal |
MalwareBlackEnergy | BlackEnergy has removed the watermark associated with enabling the |
| T1070 Indicator Removal |
MalwareRising Sun | Rising Sun can clear a memory blog in the process by overwriting it with junk bytes. |
| T1070 Indicator Removal |
MalwareFlagpro | Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. |
| T1070 Indicator Removal |
MalwareDarkWatchman | DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history. |
| T1070 Indicator Removal |
MalwareMultiLayer Wiper | MultiLayer Wiper uses a batch script to clear file system cache memory via the |
| T1070 Indicator Removal |
MalwareEVILNUM | EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| T1070 Indicator Removal |
MalwareMetamorfo | Metamorfo has a command to delete a Registry key it uses, |
| T1070 Indicator Removal |
MalwareBPFDoor | BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process. |
| T1070 Indicator Removal |
MalwareSDBbot | SDBbot has the ability to clean up and remove data structures from a compromised host. |
| T1070 Indicator Removal |
MalwareSibot | Sibot will delete an associated registry key if a certain server response is received. |
| T1070 Indicator Removal |
MalwareHermeticWiper | HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070 Indicator Removal |
MalwareSUNBURST | SUNBURST removed HTTP proxy registry values to clean up traces of execution. |
| T1070 Indicator Removal |
MalwareIPsec Helper | IPsec Helper can delete various registry keys related to its execution and use. |
| T1070 Indicator Removal |
MalwareFunnyDream | FunnyDream has the ability to clean traces of malware deployment. |
| T1070 Indicator Removal |
MalwareMaze | Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1070 Indicator Removal |
MalwareShadowPad | ShadowPad has deleted arbitrary Registry values. |
| T1070 Indicator Removal |
ToolSILENTTRINITY | SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys. |
| T1070 Indicator Removal |
ToolCSPY Downloader | CSPY Downloader has the ability to remove values it writes to the Registry. |
| T1070 Indicator Removal |
ToolRemcos | Remcos can clean saved cookies and logins from the web browser. |
| T1070 Indicator Removal |
ToolDonut | Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
| T1070.003 Clear Command History |
MalwareJ-magic | J-magic can overwrite previously executed command line arguments. |
| T1070.003 Clear Command History |
MalwareHildegard | Hildegard has used history -c to clear script shell logs. |
| T1070.003 Clear Command History |
MalwareKobalos | Kobalos can remove all command history on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.