Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareGelsemium | Gelsemium can use multiple domains and protocols in C2. |
| T1008 Fallback Channels |
ToolMythic | Mythic can use a list of C2 URLs as fallback mechanisms in case one IP or domain gets blocked. |
| T1008 Fallback Channels |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset. |
| T1008 Fallback Channels |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable. |
| T1010 Application Window Discovery |
MalwarePowerDuke | PowerDuke has a command to get text of the current foreground window. |
| T1010 Application Window Discovery |
MalwarePAKLOG | PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows. |
| T1010 Application Window Discovery |
MalwareTONESHELL | TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1010 Application Window Discovery |
MalwareNETWIRE | NETWIRE can discover and close windows on controlled systems. |
| T1010 Application Window Discovery |
MalwareAria-body | Aria-body has the ability to identify the titles of running windows on a compromised host. |
| T1010 Application Window Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running application windows. |
| T1010 Application Window Discovery |
MalwareMachete | Machete saves the window names. |
| T1010 Application Window Discovery |
MalwareInvisiMole | InvisiMole can enumerate windows and child windows on a compromised host. |
| T1010 Application Window Discovery |
MalwareWINERACK | WINERACK can enumerate active windows. |
| T1010 Application Window Discovery |
MalwareKazuar | Kazuar gathers information about opened windows. |
| T1010 Application Window Discovery |
MalwareFlagpro | Flagpro can check the name of the window displayed on the system. |
| T1010 Application Window Discovery |
MalwareROKRAT | ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing. |
| T1010 Application Window Discovery |
MalwareDarkWatchman | DarkWatchman reports window names along with keylogger information to provide application context. |
| T1010 Application Window Discovery |
MalwareDarkGate | DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the |
| T1010 Application Window Discovery |
MalwareMetamorfo | Metamorfo can enumerate all windows on the victim’s machine. |
| T1010 Application Window Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can monitor the titles of open windows to identify specific keywords. |
| T1010 Application Window Discovery |
MalwareCatchamas | Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on. |
| T1010 Application Window Discovery |
MalwareAttor | Attor can obtain application window titles and then determines which windows to perform Screen Capture on. |
| T1010 Application Window Discovery |
MalwareNightClub | NightClub can use `GetForegroundWindow` to enumerate the active window. |
| T1010 Application Window Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on window names. |
| T1010 Application Window Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating application windows. |
| T1010 Application Window Discovery |
MalwareCadelspy | Cadelspy has the ability to identify open windows on the compromised host. |
| T1010 Application Window Discovery |
MalwareHotCroissant | HotCroissant has the ability to list the names of all open windows on the infected host. |
| T1010 Application Window Discovery |
MalwarePoisonIvy | PoisonIvy captures window titles. |
| T1010 Application Window Discovery |
MalwarePLEAD | PLEAD has the ability to list open windows on the compromised host. |
| T1010 Application Window Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover application windows via execution of `EnumWindows`. |
| T1010 Application Window Discovery |
MalwareNetTraveler | NetTraveler reports window names along with keylogger information to provide application context. |
| T1010 Application Window Discovery |
MalwarenjRAT | njRAT gathers information about opened windows during the initial infection. |
| T1010 Application Window Discovery |
MalwareRemexi | Remexi has a command to capture active windows on the machine and retrieve window titles. |
| T1010 Application Window Discovery |
MalwareQakBot | QakBot has the ability to enumerate windows on a compromised host. |
| T1010 Application Window Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`. |
| T1010 Application Window Discovery |
ToolRemcos | Remcos can list all windows on victim systems. |
| T1010 Application Window Discovery |
ToolQuasarRAT | APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions. |
| T1010 Application Window Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on open windows. |
| T1011.001 Exfiltration Over Bluetooth |
MalwareFlame | Flame has a module named BeetleJuice that contains Bluetooth functionality that may be used in different ways, including transmitting encoded information from the infected system over the Bluetooth protocol, acting as a Bluetooth beacon, and identifying other Bluetooth devices in the vicinity. |
| T1012 Query Registry |
MalwareSynAck | SynAck enumerates Registry keys associated with event logs. |
| T1012 Query Registry |
MalwareBumblebee | Bumblebee can check the Registry for specific keys. |
| T1012 Query Registry |
MalwareProxysvc | Proxysvc gathers product names from the Registry key: |
| T1012 Query Registry |
MalwareStuxnet | Stuxnet searches the Registry for indicators of security programs. |
| T1012 Query Registry |
MalwarePOWRUNER | POWRUNER may query the Registry by running |
| T1012 Query Registry |
MalwareUrsnif | Ursnif has used Reg to query the Registry for installed programs. |
| T1012 Query Registry |
MalwarePOWERSOURCE | POWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence. |
| T1012 Query Registry |
MalwareZeus Panda | Zeus Panda checks for the existence of a Registry key and if it contains certain values. |
| T1012 Query Registry |
MalwareBankshot | Bankshot searches for certain Registry keys to be configured before executing the payload. |
| T1012 Query Registry |
MalwareBrave Prince | Brave Prince gathers information about the Registry. |
| T1012 Query Registry |
MalwareTinyTurla | TinyTurla can query the Registry for its configuration information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.