Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685.006 Clear Linux or Mac System Logs |
GroupSalt Typhoon | Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp. |
| T1685.006 Clear Linux or Mac System Logs |
GroupTeamTNT | TeamTNT has removed system logs from |
| T1685.006 Clear Linux or Mac System Logs |
GroupRocke | Rocke has cleared log files within the /var/log/ folder. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSea Turtle | Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions. |
| T1686 Disable or Modify System Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
| T1686 Disable or Modify System Firewall |
GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
| T1686 Disable or Modify System Firewall |
GroupSalt Typhoon | Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices. |
| T1686 Disable or Modify System Firewall |
GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
| T1686 Disable or Modify System Firewall |
GroupTeamTNT | TeamTNT has disabled |
| T1686 Disable or Modify System Firewall |
GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
| T1686 Disable or Modify System Firewall |
GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1686 Disable or Modify System Firewall |
GroupCarbanak | Carbanak may use netsh to add local firewall rule exceptions. |
| T1686 Disable or Modify System Firewall |
GroupMedusa Group | Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions. |
| T1686 Disable or Modify System Firewall |
GroupToddyCat | Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683. |
| T1686 Disable or Modify System Firewall |
GroupVelvet Ant | Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices. |
| T1686.002 Network Device Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686.003 Windows Host Firewall |
GroupMoses Staff | Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines. |
| T1686.003 Windows Host Firewall |
GroupOilRig | OilRig has modified Windows firewall rules to enable remote access. |
| T1686.003 Windows Host Firewall |
GroupMirrorFace | MirrorFace can modify the system firewall to allow communication to certain ports. |
| T1686.003 Windows Host Firewall |
GroupLazarus Group | Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh. |
| T1686.003 Windows Host Firewall |
GroupVOID MANTICORE | VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host. |
| T1686.003 Windows Host Firewall |
GroupMagic Hound | Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`. |
| T1690 Prevent Command History Logging |
GroupAPT38 | APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment. |
| T1690 Prevent Command History Logging |
GroupUNC3886 | UNC3886 has tampered with and disabled logging services on targeted systems. |
| T1690 Prevent Command History Logging |
GroupSea Turtle | Sea Turtle unset the Bash and MySQL history files on victim systems. |
| T1690 Prevent Command History Logging |
GroupMedusa Group | Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.