Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
MalwareSUPERNOVA | SUPERNOVA is a Web shell. |
| T1505.003 Web Shell |
MalwareNeo-reGeorg | Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections. |
| T1505.003 Web Shell |
MalwareFRAMESTING | FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareWIREFIRE | WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
MalwareSTEADYPULSE | STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers. |
| T1505.003 Web Shell |
MalwarePHASEJAM | PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance. |
| T1505.003 Web Shell |
MalwareSLIGHTPULSE | SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers. |
| T1505.003 Web Shell |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
| T1505.004 IIS Components |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components. |
| T1505.004 IIS Components |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence. |
| T1505.004 IIS Components |
MalwareOwaAuth | OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL. |
| T1505.004 IIS Components |
MalwareRGDoor | RGDoor establishes persistence on webservers as an IIS module. |
| T1505.004 IIS Components |
MalwareIceApple | IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities. |
| T1505.006 vSphere Installation Bundles |
GroupUNC3886 | UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors. |
| T1505.006 vSphere Installation Bundles |
MalwareVIRTUALPIE | VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs). |
| T1518 Software Discovery |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery. |
| T1518 Software Discovery |
CampaignJuicy Mix | During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed. |
| T1518 Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of installed software on the infected system. |
| T1518 Software Discovery |
GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1518 Software Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| T1518 Software Discovery |
GroupSidewinder | Sidewinder has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupMustang Panda | Mustang Panda has searched the victim system for the |
| T1518 Software Discovery |
GroupWindigo | Windigo has used a script to detect installed software on targeted systems. |
| T1518 Software Discovery |
GroupTropic Trooper | Tropic Trooper's backdoor could list the infected system's installed software. |
| T1518 Software Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupWindshift | Windshift has used malware to identify installed software. |
| T1518 Software Discovery |
GroupInception | Inception has enumerated installed software on compromised systems. |
| T1518 Software Discovery |
GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
| T1518 Software Discovery |
MalwareOrz | Orz can gather the victim's Internet Explorer version. |
| T1518 Software Discovery |
MalwareIronWind | IronWind can list installed software on targeted hosts. |
| T1518 Software Discovery |
MalwareInvisibleFerret | InvisibleFerret has gathered installed programs and running processes. |
| T1518 Software Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys. |
| T1518 Software Discovery |
MalwareWoody RAT | Woody RAT can collect .NET, PowerShell, and Python information from an infected host. |
| T1518 Software Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer has the ability to search systems for installed applications. |
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1518 Software Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can list PHP server configuration details. |
| T1518 Software Discovery |
MalwareSiloscape | Siloscape searches for the kubectl binary. |
| T1518 Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for the Telegram installation directory by enumerating the files on disk. |
| T1518 Software Discovery |
MalwareSocGholish | SocGholish can identify the victim's browser in order to serve the correct fake update page. |
| T1518 Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can enumerate running software on a targeted system. |
| T1518 Software Discovery |
MalwareLightSpy | If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration. |
| T1518 Software Discovery |
MalwareDyre | Dyre has the ability to identify installed programs on a compromised host. |
| T1518 Software Discovery |
MalwareDustySky | DustySky lists all installed software for the infected machine. |
| T1518 Software Discovery |
MalwareSVCReady | SVCReady can collect a list of installed software from an infected host. |
| T1518 Software Discovery |
MalwareCharmPower | CharmPower can list the installed applications on a compromised host. |
| T1518 Software Discovery |
MalwareBundlore | Bundlore has the ability to enumerate what browser is being used as well as version information for Safari. |
| T1518 Software Discovery |
MalwareGlassWorm | GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite. |
| T1518 Software Discovery |
MalwareMetamorfo | Metamorfo has searched the compromised system for banking applications. |
| T1518 Software Discovery |
MalwareKGH_SPY | KGH_SPY can collect information on installed applications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.