Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.005 Indicator Removal from Tools |
MalwareGravityRAT | The author of GravityRAT submitted samples to VirusTotal for testing, showing that the author modified the code to try to hide the DDE object in a different part of the document. |
| T1027.005 Indicator Removal from Tools |
MalwareInvisiMole | InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1027.005 Indicator Removal from Tools |
MalwareSUNBURST | SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT. |
| T1027.005 Indicator Removal from Tools |
MalwareDaserf | Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection. |
| T1027.005 Indicator Removal from Tools |
MalwarePenquin | Penquin can remove strings from binaries. |
| T1027.005 Indicator Removal from Tools |
MalwareQakBot | QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.005 Indicator Removal from Tools |
MalwareWaterbear | Waterbear can scramble functions not to be executed again with random values. |
| T1027.005 Indicator Removal from Tools |
ToolPowerSploit | PowerSploit's |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.