Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwarePowerDuke | PowerDuke has a command to get text of the current foreground window. |
| T1010 Application Window Discovery |
MalwarePAKLOG | PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows. |
| T1010 Application Window Discovery |
MalwareTONESHELL | TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1010 Application Window Discovery |
MalwareNETWIRE | NETWIRE can discover and close windows on controlled systems. |
| T1010 Application Window Discovery |
MalwareAria-body | Aria-body has the ability to identify the titles of running windows on a compromised host. |
| T1010 Application Window Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running application windows. |
| T1010 Application Window Discovery |
MalwareMachete | Machete saves the window names. |
| T1010 Application Window Discovery |
MalwareInvisiMole | InvisiMole can enumerate windows and child windows on a compromised host. |
| T1010 Application Window Discovery |
MalwareWINERACK | WINERACK can enumerate active windows. |
| T1010 Application Window Discovery |
MalwareKazuar | Kazuar gathers information about opened windows. |
| T1010 Application Window Discovery |
MalwareFlagpro | Flagpro can check the name of the window displayed on the system. |
| T1010 Application Window Discovery |
MalwareROKRAT | ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing. |
| T1010 Application Window Discovery |
MalwareDarkWatchman | DarkWatchman reports window names along with keylogger information to provide application context. |
| T1010 Application Window Discovery |
MalwareDarkGate | DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the |
| T1010 Application Window Discovery |
MalwareMetamorfo | Metamorfo can enumerate all windows on the victim’s machine. |
| T1010 Application Window Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can monitor the titles of open windows to identify specific keywords. |
| T1010 Application Window Discovery |
MalwareCatchamas | Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on. |
| T1010 Application Window Discovery |
MalwareAttor | Attor can obtain application window titles and then determines which windows to perform Screen Capture on. |
| T1010 Application Window Discovery |
MalwareNightClub | NightClub can use `GetForegroundWindow` to enumerate the active window. |
| T1010 Application Window Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on window names. |
| T1010 Application Window Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating application windows. |
| T1010 Application Window Discovery |
MalwareCadelspy | Cadelspy has the ability to identify open windows on the compromised host. |
| T1010 Application Window Discovery |
MalwareHotCroissant | HotCroissant has the ability to list the names of all open windows on the infected host. |
| T1010 Application Window Discovery |
MalwarePoisonIvy | PoisonIvy captures window titles. |
| T1010 Application Window Discovery |
MalwarePLEAD | PLEAD has the ability to list open windows on the compromised host. |
| T1010 Application Window Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover application windows via execution of `EnumWindows`. |
| T1010 Application Window Discovery |
MalwareNetTraveler | NetTraveler reports window names along with keylogger information to provide application context. |
| T1010 Application Window Discovery |
MalwarenjRAT | njRAT gathers information about opened windows during the initial infection. |
| T1010 Application Window Discovery |
MalwareRemexi | Remexi has a command to capture active windows on the machine and retrieve window titles. |
| T1010 Application Window Discovery |
MalwareQakBot | QakBot has the ability to enumerate windows on a compromised host. |
| T1010 Application Window Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`. |
| T1010 Application Window Discovery |
ToolRemcos | Remcos can list all windows on victim systems. |
| T1010 Application Window Discovery |
ToolQuasarRAT | APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions. |
| T1010 Application Window Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on open windows. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.