How The Activity Unfolds In ATT&CK
Operation Digital Eye is a useful modern intrusion chain: infrastructure preparation supports operations, scripting enables execution, credentials expand access, and exfiltration completes the objective.
- T1583.004 Server. Infrastructure is prepared before or during operations.
- T1059.005 Visual Basic. Script execution provides a flexible command path.
- T1003.001 LSASS Memory. Credential access supports privilege and movement.
- T1041 Exfiltration Over C2 Channel. Data exits through actor-controlled channels.
Defender Readout
This activity is useful for mapping infrastructure, execution, credential, and exfiltration telemetry across one intrusion story.
Evidence And Mapping Rationale
Server
MITRE maps the campaign to acquiring or preparing server infrastructure.
Visual Basic
MITRE maps command and scripting activity through Visual Basic.
LSASS Memory
MITRE maps credential dumping from LSASS memory to the campaign.
Exfiltration Over C2 Channel
MITRE maps data exfiltration through command-and-control channels.