Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.45
tool
Agent Tesla S0331
- Type
- malware
- Platform
- Windows
- Created
- 29 January 2019
- Last modified
- 16 April 2025
Agent Tesla is a spyware Trojan written for the .NET framework that has been observed since at least 2014.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0331
Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected.6
Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult.7 Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings.8
Agent Tesla can collect the username from the victim’s machine.91011
Agent Tesla has used wmi queries to gather information from the system.12
Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.131415
Standing S0331
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
97th percentile · 97% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
98th percentile · 98% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
48th percentile · 52% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0331
1465 distinct rules cover the 37 techniques recorded for this tool. The 1580 technique-to-rule mappings resolve to 1465 distinct rules, because one rule can cover several techniques. 933 Sigma · 532 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org