ATT&CKReferencesDell Lateral Movement

Dell Lateral Movement

Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1053.002
At
GroupAPT18

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.

T1059.003
Windows Command Shell
MalwarehcdLoader

hcdLoader provides command-line access to the compromised system.

T1070.004
File Deletion
GroupAPT18

APT18 actors deleted tools and batch files from victim systems.

T1543.003
Windows Service
MalwarehcdLoader

hcdLoader installs itself as a service for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.