ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1685.006
Clear Linux or Mac System Logs
GroupSalt Typhoon

Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp.

T1685.006
Clear Linux or Mac System Logs
GroupTeamTNT

TeamTNT has removed system logs from /var/log/syslog.

T1685.006
Clear Linux or Mac System Logs
GroupRocke

Rocke has cleared log files within the /var/log/ folder.

T1685.006
Clear Linux or Mac System Logs
GroupSea Turtle

Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.

T1686
Disable or Modify System Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

T1686
Disable or Modify System Firewall
GroupKimsuky

Kimsuky has been observed disabling the system firewall.

T1686
Disable or Modify System Firewall
GroupSalt Typhoon

Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices.

T1686
Disable or Modify System Firewall
GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

T1686
Disable or Modify System Firewall
GroupTeamTNT

TeamTNT has disabled iptables.

T1686
Disable or Modify System Firewall
GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

T1686
Disable or Modify System Firewall
GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1686
Disable or Modify System Firewall
GroupCarbanak

Carbanak may use netsh to add local firewall rule exceptions.

T1686
Disable or Modify System Firewall
GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

T1686
Disable or Modify System Firewall
GroupToddyCat

Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683.

T1686
Disable or Modify System Firewall
GroupVelvet Ant

Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices.

T1686.002
Network Device Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686.003
Windows Host Firewall
GroupMoses Staff

Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines.

T1686.003
Windows Host Firewall
GroupOilRig

OilRig has modified Windows firewall rules to enable remote access.

T1686.003
Windows Host Firewall
GroupMirrorFace

MirrorFace can modify the system firewall to allow communication to certain ports.

T1686.003
Windows Host Firewall
GroupLazarus Group

Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh.

T1686.003
Windows Host Firewall
GroupVOID MANTICORE

VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host.

T1686.003
Windows Host Firewall
GroupMagic Hound

Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`.

T1690
Prevent Command History Logging
GroupAPT38

APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment.

T1690
Prevent Command History Logging
GroupUNC3886

UNC3886 has tampered with and disabled logging services on targeted systems.

T1690
Prevent Command History Logging
GroupSea Turtle

Sea Turtle unset the Bash and MySQL history files on victim systems.

T1690
Prevent Command History Logging
GroupMedusa Group

Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.