Miller, S, et al. (2019, April 10). TRITON Actor TTP Profile, Custom Attack Tools, Detections, and ATT&CK Mapping. Retrieved April 16, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| T1021.001 Remote Desktop Protocol |
CampaignC0032 | During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| T1021.004 SSH |
CampaignC0032 | During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0032 | During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1053.005 Scheduled Task |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used scheduled task XML triggers. |
| T1059.001 PowerShell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| T1070.004 File Deletion |
CampaignC0032 | During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them. |
| T1070.006 Timestomp |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used timestomping to modify the |
| T1074.001 Local Data Staging |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
| T1078 Valid Accounts |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| T1133 External Remote Services |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment. |
| T1505.003 Web Shell |
CampaignC0032 | During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| T1546.012 Image File Execution Options Injection |
CampaignC0032 | During the C0032 campaign, TEMP.Veles modified and added entries within |
| T1571 Non-Standard Port |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2. |
| T1572 Protocol Tunneling |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment. |
| T1583.003 Virtual Private Server |
CampaignC0032 | During the C0032 campaign, TEMP.Veles used Virtual Private Server (VPS) infrastructure. |
| T1588.002 Tool |
CampaignC0032 | During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.