Log Enumeration

T1654

Technique.View on attack.mitre.org

About this technique

Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account Discovery), security or vulnerable software (Software Discovery), or hosts within a compromised network (Remote System Discovery).

Host binaries may be leveraged to collect system logs. Examples include using `wevtutil.exe` or PowerShell on Windows to access and/or export security event information. In cloud environments, adversaries may leverage utilities such as the Azure VM Agent’s `CollectGuestLogs.exe` to collect security logs from cloud hosted infrastructure.

Adversaries may also target centralized logging infrastructure such as SIEMs. Logs may also be bulk exported and sent to adversary-controlled infrastructure for offline analysis.

In addition to gaining a better understanding of the environment, adversaries may also monitor logs in real time to track incident response procedures. This may allow them to adjust their techniques in order to maintain persistence or evade defenses.

Detection rules2

Rules on DetectionCode tagged with T1654.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk2

RuleTypeRiskData source
Splunk Authentication Token Exposure in Debug LogTTPNULL
Windows EventLog Recon Activity Using Log Query UtilitiesAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups5

Software5

Campaigns0

None recorded.

Procedure examples10

Groups5

Used byProcedure example
GroupAPT5

APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs.

GroupAquatic Panda

Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.

GroupEmber Bear

Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions.

GroupMustang Panda

Mustang Panda has used Wevtutil to gather Windows Security Event Logs.

GroupVolt Typhoon

Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.

Software5

Used byProcedure example
MalwareAkira _v2

Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.

MalwareBeaverTail

BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration.

MalwareDUSTTRAP

DUSTTRAP can identify infected system log information.

MalwareMegazord

Megazord has the ability to print the trace, debug, error, info, and warning logs.

ToolPacu

Pacu can collect CloudTrail event histories and CloudWatch logs.

References4

  1. Cadet Blizzard emerges as novel threat actor Open source
    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
  2. Permiso GUI-Vil 2023 Open source
    Ian Ahl. (2023, May 22). Unmasking GUI-Vil: Financially Motivated Cloud Threat Actor. Retrieved August 30, 2024.
  3. SIM Swapping and Abuse of the Microsoft Azure Serial Console Open source
    Mandiant Intelligence. (2023, May 16). SIM Swapping and Abuse of the Microsoft Azure Serial Console: Serial Is Part of a Well Balanced Attack. Retrieved June 2, 2023.
  4. WithSecure Lazarus-NoPineapple Threat Intel Report 2023 Open source
    Ruohonen, S. & Robinson, S. (2023, February 2). No Pineapple! -DPRK Targeting of Medical Research and Technology Sector. Retrieved July 10, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.