ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Defending against cyber-attacks using the MITRE ATT&CK framework

In the third article of his three-part series, Adrian Bishop at Huntsman Security explains how attackers steal sensitive data and the steps that organisations can take to defend themselves

 

In this three-part series analysing a hypothetical cyber-attack, we have already seen how attackers gather information about a network, including credentials and accounts and then establish a persistent presence

 

Now we will investigate how attackers gather and exfiltrate sensitive data whilst preventing recovery – and the last steps that organisations can take to defend themselves.

 

Stage 9: Collection

After compromising all the required hosts on a network, the attacker will collect as much data as possible and prepare it to be transferred to another location.

 

To do so, they may install a script or utilities on to compromised hosts to scan local and network filesystems for important information and documents. Any files discovered are compressed, encrypted, and added to archive files on the local system.

 

The archive files are then moved to a single staging server and stored in locations such as the Recycle Bin to reduce the chance of discovery.

 

Within the Collection Tactic are Techniques that enable data collection from different sources and prepare it for exfiltration, including:

  • Eavesdropping on communication traffic.
  • Archiving data and staging it.
  • Capturing audio, video and screen data.
  • Automation of data collection from large repositories.
  • Capturing user input and clipboard data.
  • Capturing data from local files, removable media, emails, file shares, cloud storage, and data repositories.

Our attack scenario uses multiple Techniques to find and prepare data for exfiltration, including:

 

Stage 10: Command and Control

To gain full access to a compromised system, attackers need to establish a reliable communications channel, through which to directly execute their commands. This allows them to run commands, perform unscripted activities and control systems easier than with automated scripts and utilities.

 

In our case, the attacker ensures that periodically, each compromised system attempts to communicate with an external command and control (C2) server using either an HTTP GET request containing a custom HTTP Cookie, or on TCP port 1913 using the SOCKS5 protocol.

 

The C2 server collects basic host information and provides access to utilities and a remote access tool (RAT) which are automatically downloaded and installed. Once the RAT is installed a connection to a second command and control server is made using TCP port 81, which is then used by the attacker to interact with the system via a reverse shell.

 

The Techniques to enable this capability are within the Command and Control Tactic and include:

  • Communications within application and networking protocols or on removable media.
  • Encoding, obfuscating and encrypting communications.
  • Using multiple command and control servers and communications channels.
  • The transfer of files and tools into an environment.
  • The use of remote access tools.

The Techniques used within our attack scenario to evade detection are:

 

Stage 11: Exfiltration

The attacker uses command line access to the staging server to setup automated transfers of the encrypted archive files using two methods:

  1. The archive files are copied to \AppData\Local\Temp within the user’s home directory where they are uploaded by the RAT to the C2 server over the command and control channel; or
  2. The attacker also uses a custom utility to split the files into multiple small parts, to avoid detection, and then upload them over HTTPS to Dropbox in small batches every hour.

The exfiltration of large amounts of data can be relatively easy to spot compared with other activities performed up to this point. Attackers may therefore wait until they have gathered significant information before performing this stage. Exfiltration Techniques include:

  • Automatic and scheduled data uploads.
  • Uploads over dedicated or command and control channels.
  • Uploads to web storage services and cloud environments.

The exfiltration of data within our attack scenario uses the following Techniques:

 

Stage 12: Impact

After an attacker has exfiltrated data from the compromised hosts, they may attempt to delete or encrypt the original versions and any backups.

 

This is achieved by using the C2 server to download a utility to all compromised hosts which securely deletes all the collected documents and archive files. This will ensure that any demands for payment for copies of the files will not be rejected as the attacker now has sole possession of them.

 

The Techniques within the Impact Tactic are designed to cause damage to data and systems and include:

  • Account deletion, disablement or locking.
  • Corruption, encryption or deletion of data and data backups.
  • Defacement of systems.
  • Denial of service attacks.
  • Stopping of services or systems.

In the final stage of our attack scenario the attacker used the following Technique:

Defensive actions to protect data

MITRE ATT&CK outlines a number of tactics that organisations should undertake to defend against this kind of attack. Specifically:

  • Using data loss prevention solutions that restrict access to sensitive data.
  • Block unrequired communication channels and protocols from accessing the internet.
  • Block file uploads to unapproved external web storage services.
  • Perform regular data backups and store them on WORM drives.
  • Regularly test data backups for integrity.

A number of monitoring and detection activities are also recommended including:

  • Monitor executed commands for data search, archive and deletion activities.
  • Monitor for unusual access to data files or access to large numbers of them.
  • Monitor for access to share drives from unexpected sources.
  • Monitor for the creation of archive files in unusual locations.
  • Inspect network traffic for communications to known- bad or suspicious domains or that do not follow expected protocol standards.
  • Monitor for downloaded files created in unusual locations.
  • Monitor for unknown processes accessing data files.
  • Monitor for connections to known file storage services.
  • Monitor for large numbers of files being deleted.

As this series of articles highlights, just a single attack can employ tens of different attack techniques, each of which organisations need to defend themselves against in order to ward off an attack.

 

However, this one attack is just the tip of the iceberg. There are countless other techniques and tactics that attackers can use to compromise a system. This is what makes cyber-security so challenging and why MITRE ATT&CK is such a valuable, if overwhelming resource. 

 

To have a chance of keeping systems secure, it’s vital that organisations follow cyber-security best practice, whether that’s patching systems, monitoring their entire network or strictly controlling who they give access to. Even then, there are no guarantees that you’ll not fall victim to a breach.

 

MITRE ATT&CK provides a useful framework and best practice that can help organisations ward off attacks, but it’s still essential to ensure the basics are covered – as without doing so, the likelihood of being the next organisation in the headlines is very high.

 


 

Adrian Bishop is Head of Engineering at Huntsman Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543