Home >
Enterprise >
Participants >
Check Point >
Collection (TA0009)
|
|
Carbanak+FIN7 |
||||||||
Step | ATT&CK Pattern |
|
||||||
2.B.4
|
Technique Screen Capture (T1113) |
|
||||||
5.B.5
![]() |
Technique Data from Local System (T1005) |
|
||||||
5.B.6
![]() |
Technique Data from Local System (T1005) |
|
||||||
9.A.4
|
Technique Screen Capture (T1113) |
|
||||||
9.A.5
|
Technique Data from Local System (T1005) |
|
||||||
13.B.4
|
Technique Screen Capture (T1113) |
|
||||||
18.A.2
|
Technique Screen Capture (T1113) |
|
Criteria
explorer.exe reads C:\Users\jsmith\AppData\Local\Temp\Klog2.txt over to 192.168.0.4
Data Sources
- File Monitoring
- Process Monitoring
- Network Monitoring