Home >
Enterprise >
Participants >
BlackBerry Cylance >
Lateral Tool Transfer (T1570)
|
|
Carbanak+FIN7 |
||||||
Step | ATT&CK Pattern |
|
||||
5.A.9
![]() |
Tactic Lateral Movement (TA0008) |
|
||||
5.A.10
![]() |
Tactic Lateral Movement (TA0008) |
|
||||
5.A.11
![]() |
Tactic Lateral Movement (TA0008) |
|
||||
5.C.4
|
Tactic Lateral Movement (TA0008) |
|
Criteria
Pscp.exe copies psexec.py to 10.0.0.7
Data Sources
- Network Monitoring
- File Monitoring
- Process Monitoring
Footnotes
- Remote Response/Host Interrogation
- MITRE confirmed detection without screenshots
Criteria
Pscp.exe copies runtime to 10.0.0.7
Data Sources
- Process Monitoring
- File Monitoring
- Network Monitoring
Footnotes
- Remote Response/Host Interrogation
- MITRE confirmed detection without screenshots
Criteria
Pscp.exe copies tiny.exe to 10.0.0.7
Data Sources
- Process Monitoring
- File Monitoring
- Network Monitoring
Footnotes
- MITRE confirmed detection without screenshots
- Remote Response/Host Interrogation
APT29 |
||||
Step | ATT&CK Pattern |
|
||
16.D.1
|
Tactic Lateral Movement (TA0008) |
|