ATT&CKReferencesAnomali Evasive Maneuvers July 2015

Anomali Evasive Maneuvers July 2015

Shelmire, A. (2015, July 06). Evasive Maneuvers by the Wekby group with custom ROP-packing and DNS covert channels. Retrieved November 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
GroupAPT18

APT18 uses cmd.exe to execute commands on the victim’s machine.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT18

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.