Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
ToolAdFind | AdFind can extract subnet information from Active Directory. |
| T1018 Remote System Discovery |
ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| T1685 Disable or Modify Tools |
MalwareRyuk | Ryuk has stopped services related to anti-virus. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.