Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1120 Peripheral Device Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list connected devices. |
| T1123 Audio Capture |
MalwareDOGCALL | DOGCALL can capture microphone data from the victim's machine. |
| T1123 Audio Capture |
MalwareJanicab | Janicab captured audio and sent it out to a C2 server. |
| T1123 Audio Capture |
MalwareEvilGrab | EvilGrab has the capability to capture audio from a victim machine. |
| T1123 Audio Capture |
MalwareCrimson | Crimson can perform audio surveillance using microphones. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1123 Audio Capture |
MalwareInvisiMole | InvisiMole can record sound using input audio devices. |
| T1123 Audio Capture |
MalwareVERMIN | VERMIN can perform audio capture. |
| T1123 Audio Capture |
MalwareDarkComet | DarkComet can listen in to victims' conversations through the system’s microphone. |
| T1123 Audio Capture |
MalwareLightSpy | LightSpy uses Apple's built-in AVFoundation Framework library to capture and manage audio recordings then transform them to JSON blobs for exfiltration. |
| T1123 Audio Capture |
MalwareROKRAT | ROKRAT has an audio capture and eavesdropping module. |
| T1123 Audio Capture |
MalwareBandook | Bandook has modules that are capable of capturing audio. |
| T1123 Audio Capture |
MalwareT9000 | T9000 uses the Skype API to record audio and video calls. It writes encrypted data to |
| T1123 Audio Capture |
MalwareMicropsia | Micropsia can perform microphone recording. |
| T1123 Audio Capture |
MalwareAttor | Attor's has a plugin that is capable of recording audio using available input sound devices. |
| T1123 Audio Capture |
MalwareNightClub | NightClub can load a module to leverage the LAME encoder and `mciSendStringW` to control and capture audio. |
| T1123 Audio Capture |
MalwareDerusbi | Derusbi is capable of performing audio captures. |
| T1123 Audio Capture |
MalwareMgBot | MgBot can capture input and output audio streams from infected devices. |
| T1123 Audio Capture |
MalwareCadelspy | Cadelspy has the ability to record audio from the compromised host. |
| T1123 Audio Capture |
MalwareCobian RAT | Cobian RAT has a feature to perform voice recording on the victim’s machine. |
| T1123 Audio Capture |
MalwareNanoCore | NanoCore can capture audio feeds from the system. |
| T1123 Audio Capture |
MalwareTajMahal | TajMahal has the ability to capture VoiceIP application audio on an infected host. |
| T1123 Audio Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for microphone interception. |
| T1123 Audio Capture |
MalwareMacMa | MacMa has the ability to record audio. |
| T1123 Audio Capture |
MalwarejRAT | jRAT can capture microphone recordings. |
| T1123 Audio Capture |
MalwareMacSpy | MacSpy can record the sounds from microphones on a computer. |
| T1123 Audio Capture |
ToolPowerSploit | PowerSploit's |
| T1123 Audio Capture |
ToolRemcos | Remcos can capture data from the system’s microphone. |
| T1123 Audio Capture |
ToolImminent Monitor | Imminent Monitor has a remote microphone monitoring capability. |
| T1123 Audio Capture |
ToolPupy | Pupy can record sound with the microphone. |
| T1123 Audio Capture |
MalwareFlame | Flame can record audio using any existing hardware recording devices. |
| T1124 System Time Discovery |
MalwarePowerDuke | PowerDuke has commands to get the time the machine was built, the time, and the time zone. |
| T1124 System Time Discovery |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system. |
| T1124 System Time Discovery |
MalwareProxysvc | As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server. |
| T1124 System Time Discovery |
MalwareTorisma | Torisma can collect the current time on a victim machine. |
| T1124 System Time Discovery |
MalwareNOKKI | NOKKI can collect the current timestamp of the victim's machine. |
| T1124 System Time Discovery |
MalwareStuxnet | Stuxnet collects the time and date of a system when it is infected. |
| T1124 System Time Discovery |
MalwareAvosLocker | AvosLocker has checked the system time before and after encryption. |
| T1124 System Time Discovery |
MalwarePAKLOG | PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S. |
| T1124 System Time Discovery |
MalwareWindTail | WindTail has the ability to generate the current date and time. |
| T1124 System Time Discovery |
MalwareZeus Panda | Zeus Panda collects the current system time (UTC) and sends it back to the C2 server. |
| T1124 System Time Discovery |
MalwareGravityRAT | GravityRAT can obtain the date and time of a system. |
| T1124 System Time Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has discovered device uptime through `GetTickCount()`. |
| T1124 System Time Discovery |
MalwareAppleSeed | AppleSeed can pull a timestamp from the victim's machine. |
| T1124 System Time Discovery |
MalwareCrimson | Crimson has the ability to determine the date and time on a compromised host. |
| T1124 System Time Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the infected system's current time and writes it to a log file during execution. |
| T1124 System Time Discovery |
MalwareBADHATCH | BADHATCH can obtain the `DATETIME` and `UPTIME` from a compromised machine. |
| T1124 System Time Discovery |
MalwarePUBLOAD | PUBLOAD has collected the machine’s tick count through the use of `GetTickCount`. |
| T1124 System Time Discovery |
MalwareSystemBC | SystemBC has leveraged the time of the device to create a text file with a filename that uses the function of `uniqid(time()).‘.txt`, consisting of the 10 character UNIX timestamp and 13 hexadecimal characters. |
| T1124 System Time Discovery |
MalwareShrinkLocker | ShrinkLocker retrieves a system timestamp that is used in generating an encryption key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.