Home >
Enterprise >
Participants >
BlackBerry Cylance >
Automated Collection (T1119)
|
|
See technique results for:
Carbanak+FIN7 |
||
The technique was not in scope. |
APT29 |
||||||||
Step | ATT&CK Pattern |
|
||||||
2.A.2
|
Tactic Collection (TA0009) |
|
||||||
9.B.3
|
Tactic Collection (TA0009) |
|
Procedure
Scripted search of filesystem for document and media files using PowerShell
Criteria
powershell.exe executing (Get-)ChildItem
Footnotes
- Though no image was captured, MITRE confirmed that the vendor has the capability to show available telemetry in a separate view.