Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
ToolImminent Monitor | Imminent Monitor has a module for performing remote desktop access. |
| T1027 Obfuscated Files or Information |
ToolImminent Monitor | Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2. |
| T1041 Exfiltration Over C2 Channel |
ToolImminent Monitor | Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2. |
| T1056.001 Keylogging |
ToolImminent Monitor | Imminent Monitor has a keylogging module. |
| T1057 Process Discovery |
ToolImminent Monitor | Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed. |
| T1059 Command and Scripting Interpreter |
ToolImminent Monitor | Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1070.004 File Deletion |
ToolImminent Monitor | Imminent Monitor has deleted files related to its dynamic debugger feature. |
| T1083 File and Directory Discovery |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there. |
| T1106 Native API |
ToolImminent Monitor | Imminent Monitor has leveraged CreateProcessW() call to execute the debugger. |
| T1123 Audio Capture |
ToolImminent Monitor | Imminent Monitor has a remote microphone monitoring capability. |
| T1125 Video Capture |
ToolImminent Monitor | Imminent Monitor has a remote webcam monitoring capability. |
| T1140 Deobfuscate/Decode Files or Information |
ToolImminent Monitor | Imminent Monitor has decoded malware components that are then dropped to the system. |
| T1496.001 Compute Hijacking |
ToolImminent Monitor | Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine. |
| T1555.003 Credentials from Web Browsers |
ToolImminent Monitor | Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords. |
| T1564.001 Hidden Files and Directories |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden. |
| T1685 Disable or Modify Tools |
ToolImminent Monitor | Imminent Monitor has a feature to disable Windows Task Manager. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.