ATT&CKReferencesDell TG-1314

Dell TG-1314

Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
GroupThreat Group-1314

Threat Group-1314 actors mapped network drives using net use.

T1059.003
Windows Command Shell
GroupThreat Group-1314

Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands.

T1072
Software Deployment Tools
GroupThreat Group-1314

Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement.

T1078.002
Domain Accounts
GroupThreat Group-1314

Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.