T1564: T1564
Essential information
- MITRE technique ID
T1564- Confidence
- 100/100
- Revoked
- No
- Published
- 26/02/2020 18:41
- Modified
- 27/03/2026 01:10
- Author / Source
- The MITRE Corporation
Aliases
Hide Artifacts
Platforms
windows macos linux ESXi Office Suite
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (39)
-
The MITRE Corporation Confidence 100
[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.(Citation: Proofpoint…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active…
First seen 01/01/1970 · Last seen 16/11/5138 · -
DeathGrip usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Kimsuky and Andariel usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MirrorFace usesAlienVault Confidence 100
[MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has…
First seen 01/01/1970 · Last seen 16/11/5138 · -
UNC4466 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Bilalkhanicom usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Locky usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Deathstalker usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Sidewinder](https://attack.mitre.org/groups/G0121) is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (81)
-
Ntospy usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Golang usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Loki.Rat Backdoor usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Bronze Union usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Predator usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CmEx usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Zloader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MacMa usesFamily The MITRE Corporation Confidence 100
[MacMa](https://attack.mitre.org/software/S1016) is a macOS-based backdoor with a large set of functionalities to control and exfiltrate files from a compromised computer. [MacMa](https://attack.mitre.org/software/S1016) has been observed in the wild since…
First seen 01/01/1970 · Last seen 16/11/5138 · -
EKANS - S0605 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Brute Ratel C4 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ClawHavoc usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
SNAKEHOSE usesThe MITRE Corporation Confidence 100
[EKANS](https://collaborate.mitre.org/attackics/index.php/Software/S0017) is ransomware that was first seen December 2019 and later reported to have impacted operations at Honda automotive production facilities.(Citation: Forbes Snake Ransomware June 2020)(Citation: MalwareByes Honda…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (41)
-
11 MITREs 1 Malware 11 Observables
-
11 MITREs 35 Observables
-
12 MITREs 3 Malwares 2 Observables
-
7 CVEs 13 MITREs 28 Observables
-
9 MITREs 6 Malwares 23 Observables
-
14 MITREs 1 Malware
-
10 MITREs 5 Malwares 1 Observable
-
A Website Attacked related4 MITREs 1 Malware 72 Observables 1 APT
-
13 MITREs 8 Malwares 7 Observables
-
9 MITREs 13 Observables
-
10 MITREs 1 Malware 7 Observables 1 APT
-
20 MITREs 5 Malwares 3 Observables 1 APT
Vulnerabilities (CVE) (53)
Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with …
- Attack vector
- Network
- Published
- 09/10/2024
- Modified
- 21/12/2025
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. …
- Attack vector
- Network
- Published
- 25/07/2023
- Modified
- 21/12/2025
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 12/05/2017
- Modified
- 22/04/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
- Attack vector
- Local
- Complexity
- Low
- Published
- 15/11/2017
- Modified
- 29/05/2026
Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can …
- Attack vector
- Network
- Published
- 09/10/2024
- Modified
- 21/12/2025
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a …
- Published
- 07/04/2023
- Modified
- 21/12/2025
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web …
- Attack vector
- NETWORK
- Published
- 05/05/2025
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
- Attack vector
- Local
- Published
- 26/07/2023
- Modified
- 21/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 29/05/2026
Attack patterns (MITRE) (2)
-
Email Hiding Rules subtechnique-of
-
Resource Forking subtechnique-of
Course Of Action (3)
-
Application Developer Guidance mitigates
-
Antivirus/Antimalware mitigates
-
Audit mitigates