Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1686.003 Windows Host Firewall |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies the Windows firewall during execution. |
| T1686.003 Windows Host Firewall |
MalwareDarkComet | DarkComet can disable Security Center functions like the Windows Firewall. |
| T1686.003 Windows Host Firewall |
MalwareRemsec | Remsec can add or remove applications or ports on the Windows firewall or disable it entirely. |
| T1686.003 Windows Host Firewall |
MalwareTYPEFRAME | TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections. |
| T1686.003 Windows Host Firewall |
MalwareBADCALL | BADCALL disables the Windows firewall before binding to a port. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
| T1686.003 Windows Host Firewall |
MalwareHARDRAIN | HARDRAIN opens the Windows Firewall to modify incoming connections. |
| T1686.003 Windows Host Firewall |
MalwarenjRAT | njRAT has modified the Windows firewall to allow itself to communicate through the firewall. |
| T1686.003 Windows Host Firewall |
MalwareH1N1 | H1N1 kills and disables services for Windows Firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.