ATT&CKReferencesCrowdstrike HuntReport 2022

Crowdstrike HuntReport 2022

CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAquatic Panda

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1021
Remote Services
GroupAquatic Panda

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.

T1021.001
Remote Desktop Protocol
GroupAquatic Panda

Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.

T1021.002
SMB/Windows Admin Shares
GroupAquatic Panda

Aquatic Panda used remote shares to enable lateral movement in victim environments.

T1021.004
SSH
GroupAquatic Panda

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.

T1033
System Owner/User Discovery
GroupAquatic Panda

Aquatic Panda gathers information on recently logged-in users on victim devices.

T1036.004
Masquerade Task or Service
GroupAquatic Panda

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

T1036.005
Match Legitimate Resource Name or Location
GroupAquatic Panda

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.

T1047
Windows Management Instrumentation
GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

T1059.004
Unix Shell
GroupAquatic Panda

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

T1070.003
Clear Command History
GroupAquatic Panda

Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.

T1070.004
File Deletion
GroupAquatic Panda

Aquatic Panda has deleted malicious executables from compromised machines.

T1078.002
Domain Accounts
GroupAquatic Panda

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.

T1087
Account Discovery
GroupAquatic Panda

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.

T1112
Modify Registry
GroupAquatic Panda

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.

T1218.011
Rundll32
GroupAquatic Panda

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.

T1543.003
Windows Service
GroupAquatic Panda

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

T1550.002
Pass the Hash
GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

T1560.001
Archive via Utility
GroupAquatic Panda

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1574.006
Dynamic Linker Hijacking
GroupAquatic Panda

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.

T1654
Log Enumeration
GroupAquatic Panda

Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.

T1685.005
Clear Windows Event Logs
GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.