Home >
Enterprise >
Participants >
HanSight >
Ingress Tool Transfer (T1105)
|
|
APT29 |
||||||
Step | ATT&CK Pattern |
|
||||
3.A.1
|
Tactic Command and Control (TA0011) |
|
||||
4.A.1
|
Tactic Command and Control (TA0011) |
|
||||
8.B.1
|
Tactic Command and Control (TA0011) |
|
||||
9.A.1
|
Tactic Command and Control (TA0011) |
|
||||
9.A.2
|
Tactic Command and Control (TA0011) |
|
||||
14.B.3
|
Tactic Command and Control (TA0011) |
|
Procedure
Dropped additional tools (SysinternalsSuite.zip) to disk over C2 channel (192.168.0.5)
Criteria
powershell.exe creating the file SysinternalsSuite.zip
Footnotes
- Though no image was captured, MITRE confirmed that the vendor has the capability to show available telemetry in a separate view.
Procedure
Downloaded and dropped Mimikatz (m.exe) to disk
Criteria
powershell.exe downloading and/or the file write of m.exe
Footnotes
- Though no image was captured, MITRE confirmed that the vendor has the capability to show available telemetry in a separate view.