ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1040×

17 examples

TechniqueUsed byProcedure example
T1040
Network Sniffing
Malwarecd00r

cd00r can use the libpcap library to monitor captured packets for specifc sequences.

T1040
Network Sniffing
MalwareJumbledPath

JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts.

T1040
Network Sniffing
MalwareVersaMem

VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules.

T1040
Network Sniffing
MalwareCASTLETAP

CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic.

T1040
Network Sniffing
MalwareJ-magic

J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports.

T1040
Network Sniffing
MalwareEmotet

Emotet has been observed to hook network APIs to monitor network traffic.

T1040
Network Sniffing
MalwareRegin

Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB.

T1040
Network Sniffing
MalwareLine Dancer

Line Dancer can create and exfiltrate packet captures from compromised environments.

T1040
Network Sniffing
MalwareFoggyWeb

FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor.

T1040
Network Sniffing
MalwareMESSAGETAP

MESSAGETAP uses the libpcap library to listen to all traffic and parses network protocols starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP, and TCAP and finally extracts SMS message data and routing metadata.

T1040
Network Sniffing
MalwarePenquin

Penquin can sniff network traffic to look for packets matching specific conditions.

T1040
Network Sniffing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1040
Network Sniffing
ToolImpacket

Impacket can be used to sniff network traffic via an interface or raw socket.

T1040
Network Sniffing
ToolEmpire

Empire can be used to conduct packet captures on target hosts.

T1040
Network Sniffing
ToolPoshC2

PoshC2 contains a module for taking packet captures on compromised hosts.

T1040
Network Sniffing
ToolResponder

Responder captures hashes and credentials that are sent to the system after the name services have been poisoned.

T1040
Network Sniffing
ToolNBTscan

NBTscan can dump and print whole packet content.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.