Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1040 Network Sniffing |
Malwarecd00r | cd00r can use the libpcap library to monitor captured packets for specifc sequences. |
| T1040 Network Sniffing |
MalwareJumbledPath | JumbledPath has the ability to perform packet capture on remote devices via actor-defined jump-hosts. |
| T1040 Network Sniffing |
MalwareVersaMem | VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules. |
| T1040 Network Sniffing |
MalwareCASTLETAP | CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic. |
| T1040 Network Sniffing |
MalwareJ-magic | J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports. |
| T1040 Network Sniffing |
MalwareEmotet | Emotet has been observed to hook network APIs to monitor network traffic. |
| T1040 Network Sniffing |
MalwareRegin | Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB. |
| T1040 Network Sniffing |
MalwareLine Dancer | Line Dancer can create and exfiltrate packet captures from compromised environments. |
| T1040 Network Sniffing |
MalwareFoggyWeb | FoggyWeb can configure custom listeners to passively monitor all incoming HTTP GET and POST requests sent to the AD FS server from the intranet/internet and intercept HTTP requests that match the custom URI patterns defined by the actor. |
| T1040 Network Sniffing |
MalwareMESSAGETAP | MESSAGETAP uses the libpcap library to listen to all traffic and parses network protocols starting with Ethernet and IP layers. It continues parsing protocol layers including SCTP, SCCP, and TCAP and finally extracts SMS message data and routing metadata. |
| T1040 Network Sniffing |
MalwarePenquin | Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1040 Network Sniffing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1040 Network Sniffing |
ToolImpacket | Impacket can be used to sniff network traffic via an interface or raw socket. |
| T1040 Network Sniffing |
ToolEmpire | Empire can be used to conduct packet captures on target hosts. |
| T1040 Network Sniffing |
ToolPoshC2 | PoshC2 contains a module for taking packet captures on compromised hosts. |
| T1040 Network Sniffing |
ToolResponder | Responder captures hashes and credentials that are sent to the system after the name services have been poisoned. |
| T1040 Network Sniffing |
ToolNBTscan | NBTscan can dump and print whole packet content. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.