ATT&CKReferencesAlperovitch 2014

Alperovitch 2014

Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupDeep Panda

Deep Panda has used ping to identify other machines of interest.

T1021.002
SMB/Windows Admin Shares
GroupDeep Panda

Deep Panda uses net.exe to connect to network shares using net use commands with compromised credentials.

T1047
Windows Management Instrumentation
GroupDeep Panda

The Deep Panda group is known to utilize WMI for lateral movement.

T1057
Process Discovery
GroupDeep Panda

Deep Panda uses the Microsoft Tasklist utility to list processes running on systems.

T1059.001
PowerShell
GroupDeep Panda

Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk.

T1564.003
Hidden Window
GroupDeep Panda

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.