Volatile Cedar
Associated Group Descriptions |
|
Name | Description |
---|---|
Lebanese Cedar | (Citation: ClearSky Lebanese Cedar Jan 2021) |
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1595 | .002 | Active Scanning: Vulnerability Scanning |
Volatile Cedar has performed vulnerability scans of the target server.(Citation: CheckPoint Volatile Cedar March 2015)(Citation: ClearSky Lebanese Cedar Jan 2021) |
.003 | Active Scanning: Wordlist Scanning |
Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains.(Citation: ClearSky Lebanese Cedar Jan 2021) |
||
Enterprise | T1505 | .003 | Server Software Component: Web Shell |
Volatile Cedar can inject web shell code into a server.(Citation: CheckPoint Volatile Cedar March 2015)(Citation: ClearSky Lebanese Cedar Jan 2021) |
Software |
|||
ID | Name | References | Techniques |
---|---|---|---|
S0569 | Explosive | (Citation: CheckPoint Volatile Cedar March 2015) (Citation: ClearSky Lebanese Cedar Jan 2021) | System Owner/User Discovery, Keylogging, Data from Removable Media, Symmetric Cryptography, Clipboard Data, System Information Discovery, Native API, Modify Registry, System Network Configuration Discovery, Web Protocols, Ingress Tool Transfer, Hidden Files and Directories |
S0572 | Caterpillar WebShell | (Citation: CheckPoint Volatile Cedar March 2015) (Citation: ClearSky Lebanese Cedar Jan 2021) | System Owner/User Discovery, Rootkit, System Service Discovery, System Information Discovery, Data from Local System, Modify Registry, System Network Configuration Discovery, File and Directory Discovery, Process Discovery, Exfiltration Over C2 Channel, Local Groups, Brute Force, Windows Command Shell, Network Service Discovery, Ingress Tool Transfer |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.