Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Threat-Informed Defense

Browse software through a defensive analytic lens.

Use malware, tool, and utility profiles for identification, dual-use context, behavior analytics, and investigation.

S0073

ASPXSpy (S0073)

A defensive guide to the Enterprise ATT&CK software record S0073, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a web shell that can provide remote administration of a compromised web server.

Open profile →
S0092

Agent.btz (S0092)

A defensive guide to the Enterprise ATT&CK software record S0092, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a worm known for spreading through removable media.

Open profile →
S0093

Backdoor.Oldrea (S0093)

A defensive guide to the Enterprise ATT&CK software record S0093, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a modular backdoor reported in operations against energy and industrial-control environments.

Open profile →
S0099

Arp (S0099)

A defensive guide to the Enterprise ATT&CK software record S0099, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing an operating-system utility used to display or modify the Address Resolution Protocol cache.

Open profile →
S0110

at (S0110)

A defensive guide to the Enterprise ATT&CK software record S0110, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a task-scheduling utility available on several operating systems.

Open profile →
S0190

BITSAdmin (S0190)

A defensive guide to the Enterprise ATT&CK software record S0190, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a legitimate Windows command-line utility for managing Background Intelligent Transfer Service jobs.

Open profile →
S0331

Agent Tesla (S0331)

A defensive guide to the Enterprise ATT&CK software record S0331, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a .NET-based information-stealing and monitoring malware family.

Open profile →
S0344

Azorult (S0344)

A defensive guide to the Enterprise ATT&CK software record S0344, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a commercial information-stealing Trojan.

Open profile →
S0373

Astaroth (S0373)

A defensive guide to the Enterprise ATT&CK software record S0373, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a Trojan and information-stealing malware family.

Open profile →
S0422

Anubis (S0422)

A defensive guide to the Enterprise ATT&CK software record S0422, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing Android malware that evolved into a banking-trojan capability.

Open profile →
S0504

Anchor (S0504)

A defensive guide to the Enterprise ATT&CK software record S0504, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a backdoor family reported in operations that also used TrickBot.

Open profile →
S0521

BloodHound (S0521)

A defensive guide to the Enterprise ATT&CK software record S0521, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a tool that maps Active Directory relationships and attack paths for administration, assessment, or adversary use.

Open profile →
S0584

AppleJeus (S0584)

A defensive guide to the Enterprise ATT&CK software record S0584, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a family of downloaders delivered through trojanized cryptocurrency applications.

Open profile →
S0606

Bad Rabbit (S0606)

A defensive guide to the Enterprise ATT&CK software record S0606, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing self-propagating ransomware used in disruptive incidents.

Open profile →
S0677

AADInternals (S0677)

A defensive guide to the Enterprise ATT&CK software record S0677, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a PowerShell framework used to administer, enumerate, and test Azure Active Directory environments.

Open profile →
S0693

CaddyWiper (S0693)

A defensive guide to the Enterprise ATT&CK software record S0693, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a destructive data-wiping payload reported in attacks against Ukrainian organizations.

Open profile →
S1000

ACAD/Medre.A (S1000)

A defensive guide to the Enterprise ATT&CK software record S1000, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a worm that collects AutoCAD drawings and can expose operational or engineering information.

Open profile →
S1025

Amadey (S1025)

A defensive guide to the Enterprise ATT&CK software record S1025, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a Trojan bot used to establish access and retrieve additional payloads.

Open profile →
S1053

AvosLocker (S1053)

A defensive guide to the Enterprise ATT&CK software record S1053, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing ransomware offered through a ransomware-as-a-service model.

Open profile →
S1061

AbstractEmu (S1061)

A defensive guide to the Enterprise ATT&CK software record S1061, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing Android malware reported in applications that abused known exploits to obtain root permissions.

Open profile →
S1063

Brute Ratel C4 (S1063)

A defensive guide to the Enterprise ATT&CK software record S1063, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a commercial adversary-simulation platform that has also been abused in real intrusions.

Open profile →
S1070

Black Basta (S1070)

A defensive guide to the Enterprise ATT&CK software record S1070, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing ransomware associated with ransomware-as-a-service operations and Windows or ESXi targets.

Open profile →
S1087

AsyncRAT (S1087)

A defensive guide to the Enterprise ATT&CK software record S1087, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing an open-source remote administration tool that has also been used in malicious campaigns.

Open profile →
S1095

AhRat (S1095)

A defensive guide to the Enterprise ATT&CK software record S1095, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing an Android remote-access trojan derived from the AhMyth codebase.

Open profile →
S1129

Akira (S1129)

A defensive guide to the Enterprise ATT&CK software record S1129, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing ransomware associated with Akira operations and reported in Windows and ESXi variants.

Open profile →
S1133

Apostle (S1133)

A defensive guide to the Enterprise ATT&CK software record S1133, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing malware reported with destructive wiper and ransomware behavior.

Open profile →
S1167

AcidPour (S1167)

A defensive guide to the Enterprise ATT&CK software record S1167, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing an x86 Linux wiping payload designed to affect multiple embedded, networking, IoT, and industrial device types.

Open profile →
S1176

attrib (S1176)

A defensive guide to the Enterprise ATT&CK software record S1176, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a Windows utility that displays or changes file and directory attributes.

Open profile →
S1246

BeaverTail (S1246)

A defensive guide to the Enterprise ATT&CK software record S1246, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing JavaScript and C++ malware reported in credential theft and downloader activity.

Open profile →
S9031

AshTag (S9031)

A defensive guide to the Enterprise ATT&CK software record S9031, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a modular .NET backdoor tracked in public threat reporting.

Open profile →

Framework metadata remains source-controlled by MITRE.

Bare Metal Cyber profiles add original educational and defensive context. Verify current object status, relationships, and underlying references on the official ATT&CK site before using a profile for operational or attribution decisions.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.