ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1124×

14 examples

TechniqueUsed byProcedure example
T1124
System Time Discovery
GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

T1124
System Time Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system timezone.

T1124
System Time Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`.

T1124
System Time Discovery
GroupCURIUM

CURIUM deployed mechanisms to check system time information following strategic website compromise attacks.

T1124
System Time Discovery
GroupSidewinder

Sidewinder has used tools to obtain the current system time.

T1124
System Time Discovery
GroupZIRCONIUM

ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2.

T1124
System Time Discovery
GroupUNC3886

UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts.

T1124
System Time Discovery
GroupHigaisa

Higaisa used a function to gather the current time.

T1124
System Time Discovery
GroupThe White Company

The White Company has checked the current date on the victim system.

T1124
System Time Discovery
GroupTurla

Turla surveys a system upon check-in to discover the system time by using the net time command.

T1124
System Time Discovery
GroupChimera

Chimera has used time /t and net time \\ip/hostname for system time discovery.

T1124
System Time Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used net time to check the local time on a target system.

T1124
System Time Discovery
GroupDarkhotel

Darkhotel malware can obtain system time from a compromised host.

T1124
System Time Discovery
GroupLazarus Group

A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.