Technique.View on attack.mitre.org
Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account Discovery), security or vulnerable software (Software Discovery), or hosts within a compromised network (Remote System Discovery).
Host binaries may be leveraged to collect system logs. Examples include using `wevtutil.exe` or PowerShell on Windows to access and/or export security event information. In cloud environments, adversaries may leverage utilities such as the Azure VM Agent’s `CollectGuestLogs.exe` to collect security logs from cloud hosted infrastructure.
Adversaries may also target centralized logging infrastructure such as SIEMs. Logs may also be bulk exported and sent to adversary-controlled infrastructure for offline analysis.
In addition to gaining a better understanding of the environment, adversaries may also monitor logs in real time to track incident response procedures. This may allow them to adjust their techniques in order to maintain persistence or evade defenses.
Rules on DetectionCode tagged with T1654.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Splunk Authentication Token Exposure in Debug Log | TTP | NULL | |
| Windows EventLog Recon Activity Using Log Query Utilities | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT5 | APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs. |
| GroupAquatic Panda | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes. |
| GroupEmber Bear | Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions. |
| GroupMustang Panda | Mustang Panda has used Wevtutil to gather Windows Security Event Logs. |
| GroupVolt Typhoon | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons. |
| Used by | Procedure example |
|---|---|
| MalwareAkira _v2 | Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems. |
| MalwareBeaverTail | BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| MalwareDUSTTRAP | DUSTTRAP can identify infected system log information. |
| MalwareMegazord | Megazord has the ability to print the trace, debug, error, info, and warning logs. |
| ToolPacu | Pacu can collect CloudTrail event histories and CloudWatch logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.