Real-world descriptions of how a group, tool or campaign used a technique.
14 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| T1124 System Time Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system timezone. |
| T1124 System Time Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| T1124 System Time Discovery |
GroupCURIUM | CURIUM deployed mechanisms to check system time information following strategic website compromise attacks. |
| T1124 System Time Discovery |
GroupSidewinder | Sidewinder has used tools to obtain the current system time. |
| T1124 System Time Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
| T1124 System Time Discovery |
GroupUNC3886 | UNC3886 has used installation scripts to collect the system time on targeted ESXi hosts. |
| T1124 System Time Discovery |
GroupHigaisa | Higaisa used a function to gather the current time. |
| T1124 System Time Discovery |
GroupThe White Company | The White Company has checked the current date on the victim system. |
| T1124 System Time Discovery |
GroupTurla | Turla surveys a system upon check-in to discover the system time by using the |
| T1124 System Time Discovery |
GroupChimera | Chimera has used |
| T1124 System Time Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1124 System Time Discovery |
GroupDarkhotel | Darkhotel malware can obtain system time from a compromised host. |
| T1124 System Time Discovery |
GroupLazarus Group | A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.