Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1482 Domain Trust Discovery |
Tooldsquery | dsquery can be used to gather information on domain trusts with |
| T1482 Domain Trust Discovery |
ToolPoshC2 | PoshC2 has modules for enumerating domain trusts. |
| T1482 Domain Trust Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| T1482 Domain Trust Discovery |
ToolNltest | Nltest may be used to enumerate trusted domains by using commands such as |
| T1482 Domain Trust Discovery |
ToolRubeus | Rubeus can gather information about domain trusts. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| T1484.001 Group Policy Modification |
MalwarePrestige | Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller. |
| T1484.001 Group Policy Modification |
MalwareLockBit 3.0 | LockBit 3.0 can enable options for propogation through Group Policy Objects. |
| T1484.001 Group Policy Modification |
MalwareHermeticWiper | HermeticWiper has the ability to deploy through an infected system's default domain policy. |
| T1484.001 Group Policy Modification |
MalwareLockBit 2.0 | LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains. |
| T1484.001 Group Policy Modification |
MalwareEgregor | Egregor can modify the GPO to evade detection. |
| T1484.001 Group Policy Modification |
MalwareMeteor | Meteor can use group policy to push a scheduled task from the AD to all network machines. |
| T1484.001 Group Policy Modification |
MalwareQilin | Qilin has pushed a scheduled task via a Group Policy Object for payload execution. |
| T1484.001 Group Policy Modification |
ToolEmpire | Empire can use |
| T1484.002 Trust Modification |
ToolAADInternals | AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information. |
| T1485 Data Destruction |
MalwarePowerDuke | PowerDuke has a command to write random data across a file and delete it. |
| T1485 Data Destruction |
MalwareAcidRain | AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it. |
| T1485 Data Destruction |
MalwareProxysvc | Proxysvc can overwrite files indicated by the attacker before deleting them. |
| T1485 Data Destruction |
MalwareOlympic Destroyer | Olympic Destroyer overwrites files locally and on remote shares. |
| T1485 Data Destruction |
MalwareDynoWiper | DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API. |
| T1485 Data Destruction |
MalwareShrinkLocker | ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption. |
| T1485 Data Destruction |
MalwareApostle | Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, |
| T1485 Data Destruction |
MalwareWhisperGate | WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions. |
| T1485 Data Destruction |
MalwareAcidPour | AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain. |
| T1485 Data Destruction |
MalwareSameCoin | SameCoin can overwrite designated files on targeted systems with random bytes. |
| T1485 Data Destruction |
MalwareDiavol | Diavol can delete specified files from a targeted system. |
| T1485 Data Destruction |
MalwareKazuar | Kazuar can overwrite files with random data before deleting them. |
| T1485 Data Destruction |
MalwareBlackEnergy | BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents. |
| T1485 Data Destruction |
MalwareMultiLayer Wiper | MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally. |
| T1485 Data Destruction |
MalwareXbash | Xbash has destroyed Linux-based databases as part of its ransomware capabilities. |
| T1485 Data Destruction |
MalwareShamoon | Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites. |
| T1485 Data Destruction |
MalwareStoneDrill | StoneDrill has a disk wiper module that targets files other than those in the Windows directory. |
| T1485 Data Destruction |
MalwareHermeticWiper | HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1485 Data Destruction |
MalwareCaddyWiper | CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files. |
| T1485 Data Destruction |
MalwareMeteor | Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them. |
| T1485 Data Destruction |
MalwareShai-Hulud | Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices. |
| T1485 Data Destruction |
MalwareKillDisk | KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions. |
| T1485 Data Destruction |
MalwareIndustroyer | Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files. |
| T1485 Data Destruction |
MalwareLazyWiper | LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable. |
| T1485 Data Destruction |
MalwareDEADWOOD | DEADWOOD overwrites files on victim systems with random data to effectively destroy them. |
| T1485 Data Destruction |
ToolRawDisk | RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data. |
| T1485 Data Destruction |
ToolSDelete | SDelete deletes data in a way that makes it unrecoverable. |
| T1485 Data Destruction |
MalwareMini Shai-Hulud | Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary. |
| T1485 Data Destruction |
MalwareCanisterWorm | CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts. |
| T1486 Data Encrypted for Impact |
MalwareEKANS | EKANS uses standard encryption library functions to encrypt files. |
| T1486 Data Encrypted for Impact |
MalwareSynAck | SynAck encrypts the victims machine followed by asking the victim to pay a ransom. |
| T1486 Data Encrypted for Impact |
MalwareAvosLocker | AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames. |
| T1486 Data Encrypted for Impact |
MalwareRobbinHood | RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files. |
| T1486 Data Encrypted for Impact |
MalwareRansomHub | RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.