MITRE ATT&CK

Sandworm techniques

79 current technique relationships extracted from the locally archived MITRE Enterprise ATT&CK STIX collection.

collection

T1005Data from Local SystemT1213.006DatabasesT1056.001Keylogging

command and control

T1071.001Web ProtocolsT1090ProxyT1102.002Bidirectional CommunicationT1105Ingress Tool TransferT1132.001Standard EncodingT1219Remote Access ToolsT1571Non-Standard Port

credential access

T1056.001KeyloggingT1003.001LSASS MemoryT1003.003NTDST1539Steal Web Session CookieT1555.003Credentials from Web BrowsersT1040Network Sniffing

discovery

T1040Network SniffingT1018Remote System DiscoveryT1033System Owner/User DiscoveryT1049System Network Connections DiscoveryT1082System Information DiscoveryT1083File and Directory DiscoveryT1087.002Domain AccountT1087.003Email Account

execution

T1047Windows Management InstrumentationT1059.001PowerShellT1059.005Visual BasicT1106Native APIT1203Exploitation for Client ExecutionT1204.001Malicious LinkT1204.002Malicious FileT1072Software Deployment ToolsT1053.005Scheduled Task

exfiltration

T1041Exfiltration Over C2 Channel

impact

T1485Data DestructionT1486Data Encrypted for ImpactT1489Service StopT1490Inhibit System RecoveryT1491.002External DefacementT1499Endpoint Denial of ServiceT1561.002Disk Structure Wipe

initial access

T1190Exploit Public-Facing ApplicationT1195Supply Chain CompromiseT1195.002Compromise Software Supply ChainT1199Trusted RelationshipT1566.001Spearphishing AttachmentT1566.002Spearphishing LinkT1133External Remote ServicesT1078Valid AccountsT1078.002Domain Accounts

lateral movement

T1072Software Deployment ToolsT1021.002SMB/Windows Admin SharesT1570Lateral Tool Transfer

persistence

T1053.005Scheduled TaskT1505.003Web ShellT1133External Remote ServicesT1078Valid AccountsT1078.002Domain Accounts

privilege escalation

T1053.005Scheduled TaskT1078Valid AccountsT1078.002Domain Accounts

reconnaissance

T1589.002Email AddressesT1589.003Employee NamesT1590.001Domain PropertiesT1591.002Business RelationshipsT1592.002SoftwareT1593Search Open Websites/DomainsT1594Search Victim-Owned WebsitesT1595.002Vulnerability ScanningT1598.003Spearphishing Link

resource development

T1583Acquire InfrastructureT1583.001DomainsT1583.004ServerT1584.004ServerT1584.005BotnetT1585.001Social Media AccountsT1585.002Email AccountsT1586.001Social Media AccountsT1587.001MalwareT1588.002ToolT1588.006VulnerabilitiesT1608.001Upload Malware

stealth

T1027Obfuscated Files or InformationT1027.010Command ObfuscationT1036MasqueradingT1036.005Match Legitimate Resource Name or LocationT1070.004File DeletionT1140Deobfuscate/Decode Files or InformationT1218.011Rundll32T1078Valid AccountsT1078.002Domain Accounts