← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
The Jane Doe Syndrome Files: Credential Dumping and Data Exfiltration
This pulse outlines a series of techniques (Tactics) utilized in a cyber intrusion targeting Jane Doe's MacBook. These techniques span various stages of the attack lifecycle, including credential dumping (T1003), system discovery (T1016, T1082), and data exfiltration methods (T1114, T1560). The attacker employed advanced obfuscation strategies (T1027) and input capture methods (T1056) to maintain persistence and evade detection, while also utilizing command and scripting interpreters (T1059) to execute malicious commands.
Furthermore, the adversary manipulated system tokens (T1134) and leveraged remote access software (T1219) to control the compromised system. Techniques for data destruction (T1485) and artifact hiding (T1564) indicate a concerted effort to cover tracks and minimize detection.
By examining these techniques, we can better understand the methods used in this intrusion, facilitating enhanced detection and prevention strategies for future incidents.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 833 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | e20fb5a72c83cbfc8e4a8aa3943c6be8febadab7 | — | 2024-09-29 |
References (519)
↗ httpd.exp
↗ metadata.json
↗ add-class.tmpl
↗ choose-make.tmpl
↗ choose-model.tmpl
↗ choose-device.tmpl
↗ add-printer.tmpl
↗ choose-serial.tmpl
↗ class-added.tmpl
↗ choose-uri.tmpl
↗ class-confirm.tmpl
↗ admin.tmpl
↗ class-deleted.tmpl
↗ class-modified.tmpl
↗ classes-header.tmpl
↗ command.tmpl
↗ classes.tmpl
↗ edit-config.tmpl
↗ error-op.tmpl
↗ class-jobs-header.tmpl
↗ error.tmpl
↗ header.tmpl
↗ help-header.tmpl
↗ help-printable.tmpl
↗ help-trailer.tmpl
↗ job-hold.tmpl
↗ class.tmpl
↗ job-cancel.tmpl
↗ job-move.tmpl
↗ job-moved.tmpl
↗ job-release.tmpl
↗ job-restart.tmpl
↗ list-available-printers.tmpl
↗ jobs.tmpl
↗ norestart.tmpl
↗ option-boolean.tmpl
↗ option-header.tmpl
↗ option-conflict.tmpl
↗ option-pickmany.tmpl
↗ option-pickone.tmpl
↗ modify-printer.tmpl
↗ option-trailer.tmpl
↗ pager.tmpl
↗ printer-cancel-jobs.tmpl
↗ printer-added.tmpl
↗ printer-accept.tmpl
↗ printer-configured.tmpl
↗ printer-default.tmpl
↗ printer-confirm.tmpl
↗ printer-deleted.tmpl
↗ printer-jobs-header.tmpl
↗ printer-modified.tmpl
↗ jobs-header.tmpl
↗ printer-stop.tmpl
↗ modify-class.tmpl
↗ printer-reject.tmpl
↗ printers-header.tmpl
↗ printer-start.tmpl
↗ printer.tmpl
↗ printers.tmpl
↗ set-printer-options-trailer.tmpl
↗ test-page.tmpl
↗ restart.tmpl
↗ users.tmpl
↗ set-printer-options-header.tmpl
↗ search.tmpl
↗ trailer.tmpl
↗ font.defs
↗ hp.h
↗ epson.h
↗ label.h
↗ raster.defs
↗ media.defs
↗ apple.types
↗ apple.convs
↗ mime.convs
↗ mime.types
↗ cancel-current-job.test
↗ create-job-sheets.test
↗ create-job.test
↗ create-job-format.test
↗ create-job-timeout.test
↗ create-printer-subscription.test
↗ cups-create-local-printer.test
↗ fax-job.test
↗ get-completed-jobs.test
↗ get-devices.test
↗ get-job-attributes.test
↗ get-job-attributes2.test
↗ get-notifications.test
↗ get-jobs.test
↗ get-job-template-attributes.test
↗ get-ppd-printer.test
↗ get-ppds-drv-only.test
↗ get-ppd.test
↗ get-ppds-make-and-model.test
↗ get-ppds-make.test
↗ get-ppds-product.test
↗ get-ppds-psversion.test
↗ get-ppds-language.test
↗ get-printer-description-attributes.test
↗ get-ppds.test
↗ get-printer-attributes.test
↗ get-subscriptions.test
↗ identify-printer-display.test
↗ get-printers-printer-id.test
↗ identify-printer-multiple.test
↗ get-printers.test
↗ identify-printer.test
↗ get-printer-attributes-suite.test
↗ ipp-2.0.test
↗ ipp-2.2.test
↗ ipp-backend.test
↗ ipp-2.1.test
↗ print-job-and-wait.test
↗ print-job-deflate.test
↗ print-job-hold.test
↗ print-job-gzip.test
↗ ipp-1.1.test
↗ print-job-manual.test
↗ print-job-password.test
↗ print-job.test
↗ print-job-media-col.test
↗ print-uri.test
↗ print-job-letter.test
↗ set-attrs-hold.test
↗ validate-job.test
↗ ipp-everywhere.test
↗ sample.drv
↗ testprint
↗ classified
↗ standard
↗ topsecret
↗ secret
↗ confidential
↗ unclassified
↗ ntp_opendirectory.conf
↗ ntp.conf
↗ notify.conf
↗ nfs.conf
↗ nsmb.conf
↗ xtab
↗ 6015FED9-D723-4332-87D9-C478CF341407.aamdownload
↗ AuraService-fda-test
↗ com.adobe.acrobat.rna.AcroCefBrowserLock.DC
↗ ExmanProcessMutex
↗ proxy.xml
↗ A53749AF-3855-4842-A1E7-4AEFA60BD2AC
↗ XPdb-wal
↗ VZBootLoader.h
↗ VZAudioInputStreamSource.h
↗ VZBridgedNetworkDeviceAttachment.h
↗ VZAudioOutputStreamSink.h
↗ VZBridgedNetworkInterface.h
↗ VZConsoleDeviceConfiguration.h
↗ VZConsoleDevice.h
↗ VZConsolePortConfiguration.h
↗ VZDirectorySharingDevice.h
↗ VZDirectoryShare.h
↗ VZDefines.h
↗ VZDiskImageStorageDeviceAttachment.h
↗ VZDiskSynchronizationMode.h
↗ VZDiskBlockDeviceStorageDeviceAttachment.h
↗ Virtualization.h
↗ VZDirectorySharingDeviceConfiguration.h
↗ VZEntropyDeviceConfiguration.h
↗ VZEFIBootLoader.h
↗ VZError.h
↗ VZEFIVariableStore.h
↗ VZFileHandleNetworkDeviceAttachment.h
↗ VZFileHandleSerialPortAttachment.h
↗ VZFileSerialPortAttachment.h
↗ VZGraphicsDevice.h
↗ VZGenericPlatformConfiguration.h
↗ VZGenericMachineIdentifier.h
↗ VZGraphicsDeviceConfiguration.h
↗ VZGraphicsDisplayConfiguration.h
↗ VZHostAudioOutputStreamSink.h
↗ VZKeyboardConfiguration.h
↗ VZHostAudioInputStreamSource.h
↗ VZGraphicsDisplay.h
↗ VZAudioDeviceConfiguration.h
↗ VZLinuxRosettaUnixSocketCachingOptions.h
↗ VZLinuxRosettaAbstractSocketCachingOptions.h
↗ VZLinuxRosettaDirectoryShare.h
↗ VZMACAddress.h
↗ VZLinuxBootLoader.h
↗ VZMacGraphicsDevice.h
↗ VZMacGraphicsDisplay.h
↗ VZMacGraphicsDeviceConfiguration.h
↗ VZMacHardwareModel.h
↗ VZMacKeyboardConfiguration.h
↗ VZMacMachineIdentifier.h
↗ VZMacOSBootLoader.h
↗ VZLinuxRosettaCachingOptions.h
↗ VZMacOSInstaller.h
↗ VZMacOSVirtualMachineStartOptions.h
↗ VZMacOSRestoreImage.h
↗ VZMacTrackpadConfiguration.h
↗ VZMacOSConfigurationRequirements.h
↗ VZMemoryBalloonDevice.h
↗ VZMemoryBalloonDeviceConfiguration.h
↗ VZMacAuxiliaryStorage.h
↗ VZMultipleDirectoryShare.h
↗ VZMacPlatformConfiguration.h
↗ VZNetworkDevice.h
↗ VZNetworkBlockDeviceStorageDeviceAttachment.h
↗ VZNATNetworkDeviceAttachment.h
↗ VZNetworkDeviceAttachment.h
↗ VZPlatformConfiguration.h
↗ VZPointingDeviceConfiguration.h
↗ VZNetworkDeviceConfiguration.h
↗ VZSharedDirectory.h
↗ VZSerialPortAttachment.h
↗ VZNVMExpressControllerDeviceConfiguration.h
↗ VZMacGraphicsDisplayConfiguration.h
↗ VZSerialPortConfiguration.h
↗ VZSingleDirectoryShare.h
↗ VZSpiceAgentPortAttachment.h
↗ VZSocketDeviceConfiguration.h
↗ VZSocketDevice.h
↗ VZStorageDevice.h
↗ VZStorageDeviceAttachment.h
↗ VZStorageDeviceConfiguration.h
↗ VZUSBControllerConfiguration.h
↗ VZUSBDeviceConfiguration.h
↗ VZUSBMassStorageDevice.h
↗ VZUSBKeyboardConfiguration.h
↗ VZUSBController.h
↗ VZUSBDevice.h
↗ VZVirtioBlockDeviceConfiguration.h
↗ VZUSBScreenCoordinatePointingDeviceConfiguration.h
↗ VZUSBMassStorageDeviceConfiguration.h
↗ VZVirtioConsoleDevice.h
↗ VZVirtioConsoleDeviceConfiguration.h
↗ VZVirtioConsoleDeviceSerialPortConfiguration.h
↗ VZVirtioEntropyDeviceConfiguration.h
↗ VZVirtioConsolePort.h
↗ VZVirtioConsolePortConfigurationArray.h
↗ VZVirtioFileSystemDevice.h
↗ VZVirtioConsolePortConfiguration.h
↗ VZVirtioGraphicsDevice.h
↗ VZVirtioGraphicsDeviceConfiguration.h
↗ VZVirtioGraphicsScanout.h
↗ VZVirtioGraphicsScanoutConfiguration.h
↗ VZVirtioConsolePortArray.h
↗ VZVirtioFileSystemDeviceConfiguration.h
↗ VZVirtioNetworkDeviceConfiguration.h
↗ VZVirtioSocketConnection.h
↗ VZVirtioSocketDevice.h
↗ VZVirtioSoundDeviceConfiguration.h
↗ VZVirtioSocketListener.h
↗ VZVirtioSoundDeviceInputStreamConfiguration.h
↗ VZVirtioSocketDeviceConfiguration.h
↗ VZVirtioSoundDeviceOutputStreamConfiguration.h
↗ VZVirtioSoundDeviceStreamConfiguration.h
↗ VZVirtioTraditionalMemoryBalloonDeviceConfiguration.h
↗ VZVirtualMachineDelegate.h
↗ VZVirtualMachineStartOptions.h
↗ VZVirtioTraditionalMemoryBalloonDevice.h
↗ VZVirtualMachine.h
↗ VZXHCIControllerConfiguration.h
↗ VZVirtualMachineView.h
↗ VZVirtualMachineConfiguration.h
↗ VZXHCIController.h
↗ x86_64-apple-macos.swiftinterface
↗ arm64e-apple-macos.swiftinterface
↗ module.modulemap
↗ Virtualization.tbd
↗ VideoToolbox.apinotes
↗ VideoToolbox.h
↗ VTBase.h
↗ VTDecompressionProperties.h
↗ VTCompressionSession.h
↗ VTErrors.h
↗ VTCompressionProperties.h
↗ VTDecompressionSession.h
↗ VTHDRPerFrameMetadataGenerationSession.h
↗ VTMultiPassStorage.h
↗ VTPixelRotationSession.h
↗ VTFrameSilo.h
↗ VTPixelRotationProperties.h
↗ VTPixelTransferSession.h
↗ VTProfessionalVideoWorkflow.h
↗ VTRAWProcessingProperties.h
↗ VTPixelTransferProperties.h
↗ VTSession.h
↗ VTUtilities.h
↗ VTVideoEncoderList.h
↗ VTRAWProcessingSession.h
↗ libvDSP.tbd
↗ SharedWithYouCore.h
↗ SWAction.h
↗ SWCollaborationActionHandler.h
↗ SWCollaborationCoordinator.h
↗ SWCollaborationMetadata.h
↗ SWCollaborationOption.h
↗ SWCollaborationOptionsPickerGroup.h
↗ SWCollaborationOptionsGroup.h
↗ SWCollaborationShareOptions.h
↗ SWDefines.h
↗ SWPersonIdentity.h
↗ SWPerson.h
↗ SWStartCollaborationAction.h
↗ SWPersonIdentityProof.h
↗ SWUpdateCollaborationParticipantsAction.h
↗ SharedWithYouCore.tbd
↗ ScriptingBridge.tbd
↗ SBElementArray.h
↗ ScriptingBridge.apinotes
↗ ScriptingBridge.h
↗ SBApplication.h
↗ SBObject.h
↗ SCScreenshotManager.h
↗ SCError.h
↗ SCRecordingOutput.h
↗ ScreenCaptureKit.h
↗ SCShareableContent.h
↗ SCContentSharingPicker.h
↗ SCStream.h
↗ Ruby.tbd
↗ rbLibXMLParser.rb
↗ rbCFPlistError.rb
↗ rbNokogiriParser.rb
↗ rbCFTypes.rb
↗ rbCFPropertyList.rb
↗ rbPlainCFPropertyList.rb
↗ rbBinaryCFPropertyList.rb
↗ rbREXMLParser.rb
↗ cfpropertylist.rb
↗ setup.rb
↗ libxml.rb
↗ xml.rb
↗ mini_portile_cmake.rb
↗ version.rb
↗ mini_portile.rb
↗ sqlite3.rb
↗ faq.rb
↗ exception.c
↗ backup.h
↗ backup.c
↗ database.h
↗ exception.h
↗ sqlite3_ruby.h
↗ statement.h
↗ extconf.rb
↗ sqlite3.c
↗ database.c
↗ statement.c
↗ nokogiri.rb
↗ ascii.c
↗ ascii.h
↗ char_ref.h
↗ attribute.h
↗ attribute.c
↗ error.h
↗ foreign_attrs.c
↗ insertion_mode.h
↗ error.c
↗ gumbo.h
↗ parser.h
↗ replacement.h
↗ parser.c
↗ string_buffer.h
↗ string_buffer.c
↗ string_piece.c
↗ macros.h
↗ svg_attrs.c
↗ tag_lookup.h
↗ svg_tags.c
↗ tag_lookup.c
↗ token_type.h
↗ tag.c
↗ token_buffer.h
↗ token_buffer.c
↗ tokenizer.h
↗ tokenizer.c
↗ utf8.c
↗ utf8.h
↗ util.c
↗ util.h
↗ tokenizer_states.h
↗ vector.c
↗ vector.h
↗ html4_document.c
↗ html4_entity_lookup.c
↗ html4_element_description.c
↗ html4_sax_push_parser.c
↗ libxml2_backwards_compat.c
↗ nokogiri.c
↗ test_global_handlers.c
↗ xml_attribute_decl.c
↗ nokogiri.h
↗ xml_attr.c
↗ xml_cdata.c
↗ xml_document_fragment.c
↗ xml_document.c
↗ xml_element_content.c
↗ html4_sax_parser_context.c
↗ xml_encoding_handler.c
↗ xml_element_decl.c
↗ xml_entity_decl.c
↗ xml_node_set.c
↗ xml_dtd.c
↗ gumbo.c
↗ xml_namespace.c
↗ xml_processing_instruction.c
↗ xml_reader.c
↗ xml_relax_ng.c
↗ xml_entity_reference.c
↗ xml_sax_parser.c
↗ xml_sax_push_parser.c
↗ xml_sax_parser_context.c
↗ xml_text.c
↗ xml_schema.c
↗ xml_xpath_context.c
↗ xslt_stylesheet.c
↗ xml_syntax_error.c
↗ xml_comment.c
↗ xml_node.c
↗ PushKit.tbd
↗ PKPushCredentials.h
↗ PKDefines.h
↗ PKPushPayload.h
↗ PushKit.h
↗ PKPushRegistry.h
↗ PushKit.apinotes
↗ OpenDirectory.tbd
↗ ODAttributeMap.h
↗ ODMappings.h
↗ NSOpenDirectory.h
↗ ODConfiguration.h
↗ ODQuery.h
↗ ODNode.h
↗ OpenDirectory.h
↗ ODRecordMap.h
↗ ODSession.h
↗ ODModuleEntry.h
↗ ODRecord.h
↗ CFODContext.h
↗ CFODSession.h
↗ CFOpenDirectory.h
↗ CFODQuery.h
↗ CFODNode.h
↗ CFODRecord.h
↗ CFOpenDirectoryConstants.h
↗ CFOpenDirectory.tbd
↗ OpenAL.tbd
↗ alc.h
↗ al.h
↗ alut.h
↗ OpenAL.h
↗ MacOSX_OALExtensions.h
↗ arm64e-apple-ios-macabi.swiftinterface
↗ x86_64-apple-ios-macabi.swiftinterface
↗ SwiftUI.swiftoverlay
↗ MTLAccelerationStructure.h
↗ Metal.h
↗ MTLAccelerationStructureTypes.h
↗ MTLAccelerationStructureCommandEncoder.h
↗ MTLArgumentEncoder.h
↗ MTLArgument.h
↗ MTLBinaryArchive.h
↗ Metal.apinotes
↗ MTLBlitPass.h
↗ MTLBuffer.h
↗ MTLCaptureManager.h
↗ MTLCaptureScope.h
↗ MTLAllocation.h
↗ MTLCommandEncoder.h
↗ MTLCommandBuffer.h
↗ MTLComputePass.h
↗ MTLBlitCommandEncoder.h
↗ MTLCommandQueue.h
↗ MTLDefines.h
↗ MTLDepthStencil.h
↗ MTLComputePipeline.h
↗ MTLDeviceCertification.h
↗ MTLDrawable.h
↗ MTLCounters.h
↗ MTLComputeCommandEncoder.h
↗ MTLDynamicLibrary.h
↗ MTLFence.h
↗ MTLFunctionConstantValues.h
↗ MTLFunctionDescriptor.h
↗ MTLFunctionLog.h
↗ MTLFunctionHandle.h
↗ MTLEvent.h
↗ MTLFunctionStitching.h
↗ MTLHeap.h
↗ MTLDevice.h
↗ MTLIndirectCommandBuffer.h
↗ MTLIntersectionFunctionTable.h
↗ MTLIOCommandQueue.h
↗ MTLLinkedFunctions.h
↗ MTLIOCommandBuffer.h
↗ MTLIOCompressor.h
↗ MTLParallelRenderCommandEncoder.h
↗ MTLLogState.h
↗ MTLPipeline.h
↗ MTLLibrary.h
↗ MTLPixelFormat.h
↗ MTLRasterizationRate.h
↗ MTLRenderPass.h
↗ MTLRenderPipeline.h
↗ MTLResidencySet.h
↗ MTLResourceStateCommandEncoder.h
↗ MTLResourceStatePass.h
↗ MTLResource.h
↗ MTLIndirectCommandEncoder.h
↗ MTLSampler.h
↗ MTLRenderCommandEncoder.h
↗ MTLStageInputOutputDescriptor.h
↗ MTLVisibleFunctionTable.h
↗ MTLTypes.h
↗ MTLVertexDescriptor.h
↗ MTLTexture.h
↗ WebKit.arm64e.bridgesupport
↗ WebKit.bridgesupport