Meta tags:
Headings (most frequently used words):
inter, process, communication, procedure, examples, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
the (34), retrieved (33), and (30), #process (21), execution (14), ipc (14), data (13), microsoft (13), 2024 (13), all (12), for (12), may (12), with (12), 2017 (11), communication (11), att (10), security (10), inter (10), can (10), 2026 (9), use (9), november (9), pipes (9), t1559 (9), dde (8), 2025 (8), processes (8), enterprise (7), software (7), february (7), using (7), code (7), april (7), com (7), has (7), techniques (6), windows (6), registry (6), december (6), office (6), enable (6), 2023 (6), june (6), 2022 (6), via (6), pipe (6), ics (5), mobile (5), none (5), wide (5), 2018 (5), attacks (5), august (5), from (5), supply (5), chain (5), named (5), mechanisms (5), such (5), also (5), between (5), mitre (4), are (4), components (4), detection (4), objects (4), through (4), october (4), disable (4), malware (4), that (4), exchange (4), january (4), attack (4), threat (4), connect (4), rotajakiro (4), ransomware (4), march (4), remote (4), abuse (4), command (4), output (4), version (4), cti (3), mitigations (3), defenses (3), sub (3), service (3), word (3), onenote (3), excel (3), feature (3), dynamic (3), protected (3), view (3), government (3), stealbit (3), spawnchimera (3), spawning (3), ivanti (3), secure (3), exploitation (3), roadsweep (3), raspberry (3), robin (3), medusa (3), 2020 (3), hyperstack (3), compromise (3), havoc (3), cyclops (3), blink (3), 3cx (3), detects (3), apple (3), services (3), unix (3), domain (3), socket (3), shell (3), parent (3), child (3), exe (3), description (3), name (3), applications (3), set (3), created (3), when (3), toneshell (3), memory (3), other (3), share (3), standard (3), input (3), which (3), adversaries (3), component (3), object (3), model (3), corporation (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), pack (2), system (2), prevent (2), advisory (2), surface (2), reduction (2), hunting (2), suspected (2), september (2), against (2), exfiltration (2), vulnerability (2), lin (2), cutting (2), edge (2), part (2), vpn (2), 2021 (2), live (2), actor (2), teampcp (2), own (2), account (2), july (2), into (2), uses (2), 2019 (2), anomalous (2), events (2), xpc (2), injection (2), unexpected (2), send (2), privileged (2), sockets (2), correlates (2), creation (2), analytic (2), embedded (2), files (2), programs (2), not (2), modify (2), settings (2), directly (2), dcomcnfg (2), associated (2), their (2), hkey_local_machine (2), ole (2), keys (2), enabled (2), application (2), runtime (2), get (2), ability (2), uroburos (2), two (2), stdin (2), read (2), stdout (2), leveraged (2), create (2), shared (2), communicate (2), each (2), api (2), pitstop (2), during (2), operation (2), midnighteclipse (2), oilbooster (2), ninja (2), mini (2), shai (2), hulud (2), arbitrary (2), commands (2), lunarweb (2), demon (2), linux (2), 003 (2), 002 (2), 001 (2), typically (2), used (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, dcom, enhancements, server, 2003, values, setting, adv170021, defense, depth, update, dormann, ddeauto, outlook, versions, 2010, 2013, 2016, cimpanu, disables, further, 4053440, securely, opening, documents, contain, fields, nelson, reviving, brower, souza, wiltshire, what, fbi, russian, intelligence, snake, golo, muhr, joshua, chung, hive0154, targeting, philippines, pakistan, taiwan, espionage, campaign, lior, rochberger, tom, fakterman, robert, falcone, cyberespionage, southeast, asian, linked, stately, taurus, aka, mustang, panda, cybereason, global, soc, team, analysis, report, inside, lockbit, arsenal, tool, yuma, masubuchi, chimera, matt, austin, larsen, john, wolfram, ashley, pearson, josh, murchie, lukasz, lamparski, joseph, pisano, ryan, hall, ron, craft, shawn, crew, billy, wong, tyler, mclellan, post, lateral, movement, case, studies, alex, turing, hui, wang, long, secret, backdoor, jenkins, likely, iranian, conducts, politically, motivated, disruptive, activity, albanian, organizations, christopher, targets, telecom, governments, investigating, persistence, attempts, volexity, research, zero, day, unauthenticated, globalprotect, cve, 3400, hromcova, burgher, oilrig, persistent, cloud, powered, downloaders, dedola, apt, toddycat, hunt, how, python, toolkit, survives, takedown, firescale, github, victim, santos, navato, analyzing, checkmarx, kics, elementary, credential, theft, vlad, pasca, deep, dive, jurčacko, moon, back, doors, lunar, landing, diplomatic, missions, accenture, turla, carbon, kazuar, entity, ungur, haquebord, sets, sights, asus, routers, jeff, johnson, fred, plan, adrian, sanchez, renato, fontana, jake, nicastro, dimiter, andonov, marius, fodoreanu, daniel, scott, initiated, prior, north, korean, responsible, hamilton, references, mach, ports, focuses, attempting, automation, scripts, injecting, sensitive, apps, an1359, message, queues, unauthorized, suspicious, binaries, abnormal, pipelines, injected, establishing, channels, an1358, access, unusual, relationships, patterns, cmd, an1357, detect, det0493, strategy, consider, disabling, work, configuration, m1054, defaults, individual, classes, appid, appid_guid, management, m1026, specific, control, automatic, default, completely, remove, program, m1042, asr, rules, behavior, prevention, endpoint, m1040, ensure, alerts, isolation, sandboxing, m1048, hardened, capability, developing, include, entitlement, value, any, variation, true, task, allow, developer, guidance, m1013, mitigation, move, its, kernel, user, mode, generally, s0022, facilitated, dll, reverse, anonymous, write, stderr, s1239, interprocess, designation, multiple, scalable, manner, s1200, dsmdm, web, s9024, executing, non, root, permissions, known, this, allows, pid, shmget, s1078, targeted, s1150, contains, custom, network, client, communicates, primary, payload, tor, s1130, listen, over, located, cockpit, s1123, actors, wrote, then, piped, bash, c0048, results, line, unnamed, connected, s1172, redirect, s1100, executed, fed, acted, within, sys, executable, subprocess, run, s9043, createpipe, s1244, retrieve, s1141, machines, s0537, smb, s1229, s0687, veiledsignal, creates, listens, messages, modules, applejeus, c0057, procedure, examples, permalink, last, modified, macos, platforms, tactic, execute, differ, depending, but, exists, form, accessible, programming, languages, libraries, native, interfaces, environments, support, several, different, being, higher, level, mediums, those, leverage, underlying, facilitate, distributed, scripting, interpreter, local, synchronize, commonly, avoid, situations, deadlocks, occurs, stuck, cyclic, waiting, pattern, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, council, learn, more, about, started, detections, technique,
Text of the page (random words):
inter process communication technique t1559 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise inter process communication inter process communication sub techniques 3 id name t1559 001 component object model t1559 002 dynamic data exchange t1559 003 xpc services adversaries may abuse inter process communication ipc mechanisms for local code or command execution ipc is typically used by processes to share data communicate with each other or synchronize execution ipc is also commonly used to avoid situations such as deadlocks which occurs when processes are stuck in a cyclic waiting pattern adversaries may abuse ipc to execute arbitrary code or commands ipc mechanisms may differ depending on os but typically exists in a form accessible through programming languages libraries or native interfaces such as windows dynamic data exchange or component object model linux environments support several different ipc mechanisms two of which being sockets and pipes 1 higher level execution mediums such as those of command and scripting interpreter s may also leverage underlying ipc mechanisms adversaries may also use remote services such as distributed component object model to facilitate remote ipc execution 2 id t1559 sub techniques t1559 001 t1559 002 t1559 003 ⓘ tactic execution ⓘ platforms linux windows macos version 1 4 created 12 february 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0057 3cx supply chain attack during the 3cx supply chain attack applejeus s veiledsignal creates and listens on a windows named pipe to exchange messages between modules 3 s0687 cyclops blink cyclops blink has the ability to create a pipe to enable inter process communication 4 s1229 havoc the havoc smb demon can use named pipes for communication through a parent demon 5 s0537 hyperstack hyperstack can connect to the ipc share on remote machines 6 s1141 lunarweb lunarweb can retrieve output from arbitrary processes and shell commands via a pipe 7 s1244 medusa ransomware medusa ransomware has leveraged the createpipe api to enable inter process communication 8 s9043 mini shai hulud mini shai hulud has executed via the use of subprocess run and fed input through standard input stdin which acted as a pipe to send data from the parent process and the child process sys executable within memory 9 10 s1100 ninja ninja can use pipes to redirect the standard input and the standard output 11 s1172 oilbooster oilbooster can read the results of command line execution via an unnamed pipe connected to the process 12 c0048 operation midnighteclipse during operation midnighteclipse threat actors wrote output to stdout then piped it to bash for execution 13 s1123 pitstop pitstop can listen over the unix domain socket located at data runtime cockpit wd fd 14 s1130 raspberry robin raspberry robin contains an embedded custom tor network client that communicates with the primary payload via shared process memory 15 s1150 roadsweep roadsweep can pipe command output to a targeted process 16 s1078 rotajakiro when executing with non root permissions rotajakiro uses the the shmget api to create shared memory between other known rotajakiro processes this allows processes to communicate with each other and share their pid 17 s9024 spawnchimera spawnchimera has leveraged ipc using a unix domain socket between the dsmdm process and the web process 18 19 s1200 stealbit stealbit can use interprocess communication ipc to enable the designation of multiple files for exfiltration in a scalable manner 20 s1239 toneshell toneshell has facilitated inter process communication between dll components via the use of pipes 21 toneshell has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr 22 s0022 uroburos uroburos has the ability to move data between its kernel and user mode components generally using named pipes 23 mitigations id mitigation description m1013 application developer guidance enable the hardened runtime capability when developing applications do not include the com apple security get task allow entitlement with the value set to any variation of true m1048 application isolation and sandboxing ensure all com alerts and protected view are enabled 24 m1040 behavior prevention on endpoint on windows 10 enable attack surface reduction asr rules to prevent dde attacks and spawning of child processes from office programs 25 26 m1042 disable or remove feature or program registry keys specific to microsoft office feature control security can be set to disable automatic dde ole execution 27 28 29 microsoft also created and enabled by default registry keys to completely disable dde execution in word and excel 30 m1026 privileged account management modify registry settings directly or using dcomcnfg exe in hkey_local_machine software classes appid appid_guid associated with the process wide security of individual com applications 31 modify registry settings directly or using dcomcnfg exe in hkey_local_machine software microsoft ole associated with system wide security defaults for all com applications that do no set their own process wide security 32 33 m1054 software configuration consider disabling embedded files in office programs such as onenote that do not work with protected view 26 29 detection strategy id name analytic id analytic description det0493 detect abuse of inter process communication t1559 an1357 detects anomalous use of com dde or named pipes for execution correlates creation or access of ipc mechanisms e g named pipes com objects with unusual parent child process relationships or code injection patterns e g office spawning cmd exe via dde an1358 detects abuse of unix domain sockets pipes or message queues for unauthorized code execution correlates unexpected socket creation with suspicious binaries abnormal shell pipelines or injected processes establishing ipc channels an1359 detects anomalous use of mach ports apple events or xpc services for inter process execution or code injection focuses on unexpected processes attempting to send privileged apple events e g automation scripts injecting into security sensitive apps references n a 2021 april 1 inter process communication ipc retrieved march 11 2022 hamilton c 2019 june 4 hunting com objects retrieved june 10 2019 jeff johnson fred plan adrian sanchez renato fontana jake nicastro dimiter andonov marius fodoreanu daniel scott 2023 april 20 3cx software supply chain compromise initiated by a prior software supply chain compromise suspected north korean actor responsible retrieved august 25 2025 haquebord f et al 2022 march 17 cyclops blink sets sights on asus routers retrieved march 17 2022 ungur p n d havoc retrieved august 4 2025 accenture 2020 october turla uses hyperstack carbon and kazuar to compromise government entity retrieved december 2 2020 jurčacko f 2024 may 15 to the moon and back doors lunar landing in diplomatic missions retrieved june 26 2024 vlad pasca 2024 january 1 a deep dive into medusa ransomware retrieved october 15 2025 santos j and navato j r 2026 may 13 analyzing teampcp s supply chain attacks checkmarx kics and elementary data in ci cd credential theft retrieved july 16 2026 hunt io 2026 may 14 how teampcp s python toolkit survives a c2 takedown firescale github and the victim s own account retrieved july 16 2026 dedola g 2022 june 21 apt toddycat retrieved january 3 2024 hromcova z and burgher a 2023 december 14 oilrig s persistent attacks using cloud service powered downloaders retrieved november 26 2024 volexity threat research 2024 april 12 zero day exploitation of unauthenticated remote code execution vulnerability in globalprotect cve 2024 3400 retrieved november 20 2024 lin m et al 2024 february 27 cutting edge part 3 investigating ivanti connect secure vpn exploitation and persistence attempts retrieved march 1 2024 christopher so 2022 december 20 raspberry robin malware targets telecom governments retrieved may 17 2024 jenkins l at al 2022 august 4 roadsweep ransomware likely iranian threat actor conducts politically motivated disruptive activity against albanian government organizations retrieved august 6 2024 alex turing hui wang 2021 april 28 rotajakiro a long live secret backdoor with 0 vt detection retrieved june 14 2023 matt lin austin larsen john wolfram ashley pearson josh murchie lukasz lamparski joseph pisano ryan hall ron craft shawn crew billy wong tyler mclellan 2024 april 4 cutting edge part 4 ivanti connect secure vpn post exploitation lateral movement case studies retrieved april 16 2026 yuma masubuchi 2025 february 20 spawnchimera malware the chimera spawning from ivanti connect secure vulnerability retrieved april 17 2026 cybereason global soc team n d threat analysis report inside the lockbit arsenal the stealbit exfiltration tool retrieved january 29 2025 lior rochberger tom fakterman robert falcone 2023 september 22 cyberespionage attacks against southeast asian government linked to stately taurus aka mustang panda retrieved september 9 2025 golo muhr joshua chung 2025 may 15 hive0154 targeting us philippines pakistan and taiwan in suspected espionage campaign retrieved august 4 2025 fbi et al 2023 may 9 hunting russian intelligence snake malware retrieved june 8 2023 microsoft n d what is protected view retrieved november 22 2017 brower n d souza wiltshire i 2017 november 9 enable attack surface reduction retrieved february 3 2018 nelson m 2018 january 29 reviving dde using onenote and excel for code execution retrieved february 3 2018 microsoft 2017 november 8 microsoft security advisory 4053440 securely opening microsoft office documents that contain dynamic data exchange dde fields retrieved november 21 2017 cimpanu c 2017 december 15 microsoft disables dde feature in word to prevent further malware attacks retrieved december 19 2017 dormann w 2017 october 20 disable ddeauto for outlook word onenote and excel versions 2010 2013 2016 retrieved february 3 2018 microsoft 2017 december 12 adv170021 microsoft office defense in depth update retrieved february 3 2018 microsoft n d setting process wide security through the registry retrieved november 21 2017 microsoft n d registry values for system wide security retrieved november 21 2017 microsoft n d dcom security enhancements in windows xp service pack 2 and windows server 2003 service pack 1 retrieved november 22 2017 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|