Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1119 Automated Collection |
GroupPatchwork | Patchwork developed a file stealer to search C:\ and collect files with certain extensions. Patchwork also executed a script to enumerate all drives, store them as a list, and upload generated files to the C2 server. |
| T1119 Automated Collection |
GroupmenuPass | menuPass has used the Csvde tool to collect Active Directory files and data. |
| T1119 Automated Collection |
GroupHAFNIUM | HAFNIUM has used MSGraph to exfiltrate data from email, OneDrive, and SharePoint. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1119 Automated Collection |
GroupGamaredon Group | Gamaredon Group has deployed scripts on compromised systems that automatically scan for interesting documents. |
| T1119 Automated Collection |
GroupSidewinder | Sidewinder has used tools to automatically collect system and network configuration information. |
| T1119 Automated Collection |
GroupMustang Panda | Mustang Panda used custom batch scripts to collect files automatically from a targeted system. |
| T1119 Automated Collection |
GroupOilRig | OilRig has used automated collection. |
| T1119 Automated Collection |
GroupTropic Trooper | Tropic Trooper has collected information automatically using the adversary's USBferry attack. |
| T1119 Automated Collection |
GroupKe3chang | Ke3chang has performed frequent and scheduled data collection from victim networks. |
| T1119 Automated Collection |
GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1119 Automated Collection |
GroupConfucius | Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
| T1119 Automated Collection |
GroupWinter Vivern | Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP. |
| T1119 Automated Collection |
GroupRedCurl | RedCurl has used batch scripts to collect data. |
| T1119 Automated Collection |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1119 Automated Collection |
GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| T1119 Automated Collection |
GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| T1119 Automated Collection |
GroupAgrius | Agrius used a custom tool, |
| T1119 Automated Collection |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1119 Automated Collection |
GroupVOID MANTICORE | VOID MANTICORE conducted large-scale data exfiltration in the Stryker operation, consistent with automated or scripted collection against enterprise systems. |
| T1119 Automated Collection |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.