Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.004 DNS |
MalwareHelminth | Helminth can use DNS for C2. |
| T1071.004 DNS |
MalwareDenis | Denis has used DNS tunneling for C2 communications. |
| T1071.004 DNS |
ToolSliver | Sliver can support C2 communications over DNS. |
| T1071.004 DNS |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1071.004 DNS |
ToolMythic | Mythic supports DNS-based C2 profiles. |
| T1071.005 Publish/Subscribe Protocols |
MalwareGLOOXMAIL | GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2. |
| T1072 Software Deployment Tools |
MalwareWiper | It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware. |
| T1074 Data Staged |
MalwareQUIETCANARY | QUIETCANARY has the ability to stage data prior to exfiltration. |
| T1074 Data Staged |
MalwareShark | Shark has stored information in folders named `U1` and `U2` prior to exfiltration. |
| T1074 Data Staged |
MalwareKobalos | Kobalos can write captured SSH connection credentials to a file under the |
| T1074 Data Staged |
MalwareKevin | Kevin can create directories to store logs and other collected data. |
| T1074.001 Local Data Staging |
MalwareExaramel for Windows | Exaramel for Windows specifies a path to store files scheduled for exfiltration. |
| T1074.001 Local Data Staging |
MalwareNOKKI | NOKKI can collect data from the victim and stage it in |
| T1074.001 Local Data Staging |
MalwareKOPILUWAK | KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine. |
| T1074.001 Local Data Staging |
MalwareVersaMem | VersaMem staged captured credentials locally at `/tmp/.temp.data`. |
| T1074.001 Local Data Staging |
MalwarePAKLOG | PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`. |
| T1074.001 Local Data Staging |
MalwareUrsnif | Ursnif has used tmp files to stage gathered information. |
| T1074.001 Local Data Staging |
MalwareFrameworkPOS | FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\. |
| T1074.001 Local Data Staging |
MalwareInvisibleFerret | InvisibleFerret has staged data in consolidated folders prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareRainyDay | RainyDay can use a file exfiltration tool to copy files to |
| T1074.001 Local Data Staging |
MalwareAppleSeed | AppleSeed can stage files in a central location prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareNETWIRE | NETWIRE has the ability to write collected data to a file created in the |
| T1074.001 Local Data Staging |
MalwareMirrorStealer | MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`. |
| T1074.001 Local Data Staging |
MalwareTurian | Turian can store copied files in a specific directory prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMachete | Machete stores files and logs in a folder on the local drive. |
| T1074.001 Local Data Staging |
MalwarePowerLess | PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`. |
| T1074.001 Local Data Staging |
MalwarePrikormka | Prikormka creates a directory, |
| T1074.001 Local Data Staging |
MalwareMafalda | Mafalda can place retrieved files into a destination directory. |
| T1074.001 Local Data Staging |
MalwareAuTo Stealer | AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareSombRAT | SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareFLASHFLOOD | FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory. |
| T1074.001 Local Data Staging |
MalwareLoFiSe | LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders. |
| T1074.001 Local Data Staging |
MalwareCuckoo Stealer | Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1074.001 Local Data Staging |
MalwareMarkiRAT | MarkiRAT can store collected data locally in a created .nfo file. |
| T1074.001 Local Data Staging |
MalwareKazuar | Kazuar stages command output and collected data in files before exfiltration. |
| T1074.001 Local Data Staging |
MalwareNavRAT | NavRAT writes multiple outputs to a TMP file using the >> method. |
| T1074.001 Local Data Staging |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value. |
| T1074.001 Local Data Staging |
MalwareChrommme | Chrommme can store captured system information locally prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareObliqueRAT | ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories. |
| T1074.001 Local Data Staging |
MalwareSocGholish | SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`. |
| T1074.001 Local Data Staging |
MalwarePUNCHBUGGY | PUNCHBUGGY has saved information to a random temp file before exfil. |
| T1074.001 Local Data Staging |
MalwarePteranodon | Pteranodon creates various subdirectories under |
| T1074.001 Local Data Staging |
MalwareBeaverTail | BeaverTail has staged collected data to the system’s temporary directory. |
| T1074.001 Local Data Staging |
MalwareDarkWatchman | DarkWatchman can stage local data in the Windows Registry. |
| T1074.001 Local Data Staging |
MalwareDyre | Dyre has the ability to create files in a TEMP folder to act as a database to store information. |
| T1074.001 Local Data Staging |
MalwarePACEMAKER | PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`. |
| T1074.001 Local Data Staging |
MalwarePlugX | PlugX has collected and staged the victim’s computer files for exfiltration. |
| T1074.001 Local Data Staging |
MalwareLumma Stealer | Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1074.001 Local Data Staging |
MalwareDustySky | DustySky created folders in temp directories to host collected files before exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.