Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1222.001 Windows Permissions |
MalwareWastedLocker | WastedLocker has a command to take ownership of a file and reset the ACL permissions using the |
| T1222.001 Windows Permissions |
MalwareBlackCat | BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks. |
| T1222.001 Windows Permissions |
MalwareWannaCry | WannaCry uses |
| T1222.001 Windows Permissions |
MalwareBlackByte Ransomware | BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| T1222.001 Windows Permissions |
MalwareGrandoreiro | Grandoreiro can modify the binary ACL to prevent security tools from running. |
| T1222.001 Windows Permissions |
MalwareRyuk | Ryuk can launch |
| T1222.001 Windows Permissions |
MalwareCaddyWiper | CaddyWiper can modify ACL entries to take ownership of files. |
| T1222.001 Windows Permissions |
MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1222.001 Windows Permissions |
MalwareBitPaymer | BitPaymer can use |
| T1222.001 Windows Permissions |
ToolDiskpart | Diskpart can be used to display, set, or clear attributes of a disk or volume. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.