Meta tags:
Headings (most frequently used words):
power, settings, procedure, examples, mitigations, detection, strategy, references,
Text of the page (most frequently used words):
and (14), all (12), the (10), att (10), 2023 (10), system (10), #settings (10), retrieved (8), june (8), enterprise (7), techniques (7), line (7), power (7), may (7), sleep (6), hibernate (6), can (6), ics (5), mobile (5), none (5), with (5), process (5), for (5), reboot (5), mitre (4), detection (4), malware (4), down (4), execution (4), persistence (4), infected (4), version (4), adversaries (4), software (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), 2024 (3), arcanedoor (3), devices (3), cve (3), windows (3), systemd (3), powercfg (3), command (3), should (3), shut (3), files (3), activity (3), abnormal (3), configuration (3), description (3), that (3), malicious (3), dancer (3), runner (3), machines (3), 2026 (2), corporation (2), are (2), preferences (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), cisco (2), new (2), campaign (2), found (2), network (2), 2025 (2), september (2), november (2), conf (2), linux (2), monitor (2), standby (2), unexpected (2), modifications (2), correlated (2), utilities (2), modifying (2), indicate (2), strategy (2), abuse (2), analytic (2), name (2), used (2), 20353 (2), victim (2), unzipping (2), crash (2), dump (2), october (2), t1653 (2), some (2), abused (2), from (2), extend (2), timeout (2), such (2), access (2), state (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, website, changelog, privacy, policy, terms, use, contact, reset, filters, talos, april, espionage, focused, targeting, perimeter, january, joie, salvio, roy, tay, condi, ddos, botnet, spreads, via, link, 1389, avira, 2019, coinloader, sophisticated, loader, bethany, hardin, lavine, oluoch, tatiana, vollbrecht, 2022, batloader, evasive, downloader, douglas, bonderud, 2018, two, monero, attacks, target, android, users, man7, manual, page, microsoft, 2021, december, options, avg, you, your, mac, laptop, references, pmset, executions, altering, parameters, library, systemconfiguration, com, apple, powermanagement, plist, similar, an1176, detect, systemctl, inhibit, systemdsleep, behavior, edits, etc, identify, an1175, exe, arguments, display, timeouts, repeated, outside, administrative, baselines, attempts, correlate, creation, registry, changes, build, behavioral, chains, an1174, det0417, periodically, inspect, systems, activty, audit, m1047, mitigation, trigger, installing, payload, s1188, modify, skip, generation, proceed, directly, device, both, forensic, evasion, purposes, s1186, involved, exploitation, force, asa, triggering, automated, implant, c0046, procedure, examples, live, permalink, last, modified, created, juan, tapiador, menachem, goldstein, contributors, macos, platforms, tactic, aware, cannot, survive, reboots, entirely, delete, invoke, example, controls, configurable, prevent, host, locking, shutting, also, lock, screen, other, relevant, disk, similarly, keep, machine, running, even, user, active, maintain, preventing, entering, terminate, impair, ability, order, when, computer, enters, dormant, hardware, cease, operate, which, disrupt, home, open, join, mclean, hotel, location, details, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
power settings technique t1653 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise power settings power settings adversaries may impair a system s ability to hibernate reboot or shut down in order to extend access to infected machines when a computer enters a dormant state some or all software and hardware may cease to operate which can disrupt malicious activity 1 adversaries may abuse system utilities and configuration settings to maintain access by preventing machines from entering a state such as standby that can terminate malicious activity 2 3 for example powercfg controls all configurable power system settings on a windows system and can be abused to prevent an infected host from locking or shutting down 4 adversaries may also extend system lock screen timeout settings 5 other relevant settings such as disk and hibernate timeout can be similarly abused to keep the infected machine running even if no user is active 6 aware that some malware cannot survive system reboots adversaries may entirely delete files used to invoke system shut down or reboot 7 id t1653 sub techniques no sub techniques ⓘ tactic persistence ⓘ platforms linux network devices windows macos contributors juan tapiador menachem goldstein version 1 1 created 05 june 2023 last modified 24 october 2025 version permalink live version procedure examples id name description c0046 arcanedoor arcanedoor involved exploitation of cve 2024 20353 to force a victim cisco asa to reboot triggering the automated unzipping and execution of the line runner implant 8 s1186 line dancer line dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes 8 s1188 line runner line runner used cve 2024 20353 to trigger victim devices to reboot in the process unzipping and installing the line dancer payload 8 mitigations id mitigation description m1047 audit periodically inspect systems for abnormal and unexpected power settings that may indicate malicious activty detection strategy id name analytic id analytic description det0417 detection strategy for power settings abuse an1174 monitor command execution of powercfg exe with arguments modifying sleep hibernate or display timeouts abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts correlate process creation with registry and system configuration changes to build behavioral chains an1175 detect execution of system utilities systemctl systemd inhibit systemdsleep modifying sleep or hibernate behavior abnormal edits to system configuration files e g etc systemd sleep conf should be correlated with process execution to identify persistence techniques an1176 monitor pmset command executions altering sleep hibernate standby parameters unexpected modifications to library preferences systemconfiguration com apple powermanagement plist or similar files should be correlated with process activity references avg n d should you shut down sleep or hibernate your pc or mac laptop retrieved june 8 2023 microsoft 2021 december 15 powercfg command line options retrieved june 5 2023 man7 n d systemd sleep conf 5 linux manual page retrieved june 7 2023 douglas bonderud 2018 september 17 two new monero malware attacks target windows and android users retrieved june 5 2023 bethany hardin lavine oluoch tatiana vollbrecht 2022 november 14 batloader the evasive downloader malware retrieved june 5 2023 avira 2019 november 28 coinloader a sophisticated malware loader campaign retrieved june 5 2023 joie salvio and roy tay 2023 june 20 condi ddos botnet spreads via tp link s cve 2023 1389 retrieved september 5 2023 cisco talos 2024 april 24 arcanedoor new espionage focused campaign found targeting perimeter network devices retrieved january 6 2025 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|