Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| T1027 Obfuscated Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory. |
| T1106 Native API |
ToolBrute Ratel C4 | Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion. |
| T1497.003 Time Based Checks |
ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| T1620 Reflective Code Loading |
ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| T1685 Disable or Modify Tools |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.