{"description": "Enterprise techniques used by Exbyte, ATT&CK software S1179 (v1.0)", "name": "Exbyte (S1179)", "domain": "enterprise-attack", "versions": {"layer": "4.5", "attack": "17", "navigator": "5.1.0"}, "techniques": [{"techniqueID": "T1140", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) decodes and decrypts data stored in the configuration file with a key provided on the command line during execution.(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1480", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) checks for the presence of a configuration file before completing execution.(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1567", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) exfiltrates collected data to online file hosting sites such as `Mega.co.nz`.(Citation: Symantec BlackByte 2022)(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1083", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.(Citation: Symantec BlackByte 2022)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1070", "showSubtechniques": true}, {"techniqueID": "T1070.004", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) will self-delete if a hard-coded configuration file is not found.(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1106", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges.(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": false}, {"techniqueID": "T1069", "showSubtechniques": true}, {"techniqueID": "T1069.001", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) checks whether the process is running with privileged local access during execution.(Citation: Microsoft BlackByte 2023)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1518", "showSubtechniques": true}, {"techniqueID": "T1518.001", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) checks for the presence of various security software products during execution.(Citation: Symantec BlackByte 2022)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}, {"techniqueID": "T1497", "showSubtechniques": true}, {"techniqueID": "T1497.001", "comment": "[Exbyte](https://attack.mitre.org/software/S1179) performs various checks to determine if it is running in a sandboxed environment to prevent analysis.(Citation: Symantec BlackByte 2022)", "score": 1, "color": "#66b1ff", "showSubtechniques": true}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Exbyte", "color": "#66b1ff"}]}