ATT&CKReferencesFireEye EPS Awakens Part 2

FireEye EPS Awakens Part 2

Winters, R. (2015, December 20). The EPS Awakens - Part 2. Retrieved January 22, 2016.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareELMER

ELMER is capable of performing process listings.

T1071.001
Web Protocols
MalwareELMER

ELMER uses HTTP for command and control.

T1083
File and Directory Discovery
MalwareELMER

ELMER is capable of performing directory listings.

T1584.004
Server
GroupAPT16

APT16 has compromised otherwise legitimate sites as staging servers for second-stage payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.