ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareRogueRobin

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1027.010
Command Obfuscation
MalwareSQLRat

SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters.

T1027.010
Command Obfuscation
MalwareSibot

Sibot has obfuscated scripts used in execution.

T1027.010
Command Obfuscation
MalwareBackConfig

BackConfig has used compressed and decimal encoded VBS scripts.

T1027.010
Command Obfuscation
MalwarePHASEJAM

PHASEJAM has encoded commands with Base64.

T1027.010
Command Obfuscation
MalwarePoetRAT

PoetRAT has `pyminifier` to obfuscate scripts.

T1027.010
Command Obfuscation
MalwarePowerPunch

PowerPunch can use Base64-encoded scripts.

T1027.010
Command Obfuscation
MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.010
Command Obfuscation
MalwareIceApple

IceApple can use Base64 and "junk" JavaScript code to obfuscate information.

T1027.010
Command Obfuscation
MalwareKOCTOPUS

KOCTOPUS has obfuscated scripts with the BatchEncryption tool.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1027.010
Command Obfuscation
MalwareAstaroth

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

T1027.010
Command Obfuscation
MalwareQakBot

QakBot can use obfuscated and encoded scripts.

T1027.010
Command Obfuscation
MalwareCookieMiner

CookieMiner has used base64 encoding to obfuscate scripts on the system.

T1027.010
Command Obfuscation
MalwareDenis

Denis has encoded its PowerShell commands in Base64.

T1027.010
Command Obfuscation
MalwareLoudMiner

LoudMiner has obfuscated various scripts.

T1027.010
Command Obfuscation
MalwareXORIndex Loader

XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder.

T1027.010
Command Obfuscation
ToolPowerSploit

PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads.

T1027.010
Command Obfuscation
ToolEmpire

Empire has the ability to obfuscate commands using Invoke-Obfuscation.

T1027.011
Fileless Storage
MalwarePikabot

Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine.

T1027.011
Fileless Storage
MalwareRCSession

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1027.011
Fileless Storage
MalwareExaramel for Windows

Exaramel for Windows stores the backdoor's configuration in the Registry in XML format.

T1027.011
Fileless Storage
MalwareThreatNeedle

ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1027.011
Fileless Storage
MalwareNETWIRE

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.

T1027.011
Fileless Storage
MalwareTinyTurla

TinyTurla can save its configuration parameters in the Registry.

T1027.011
Fileless Storage
MalwarePolyglotDuke

PolyglotDuke can store encrypted JSON configuration files in the Registry.

T1027.011
Fileless Storage
MalwareRegDuke

RegDuke can store its encryption key in the Registry.

T1027.011
Fileless Storage
MalwareVolgmer

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1027.011
Fileless Storage
MalwareDarkWatchman

DarkWatchman can store configuration strings, keylogger, and output of components in the Registry.

T1027.011
Fileless Storage
MalwareChaes

Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry.

T1027.011
Fileless Storage
MalwareTYPEFRAME

TYPEFRAME can install and store encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1027.011
Fileless Storage
MalwareQUADAGENT

QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive.

T1027.011
Fileless Storage
MalwareUroburos

Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.`

T1027.011
Fileless Storage
MalwarePipeMon

PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`.

T1027.011
Fileless Storage
MalwareMosquito

Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft\[dllname].

T1027.011
Fileless Storage
MalwareGrandoreiro

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1027.011
Fileless Storage
MalwareSibot

Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.

T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.011
Fileless Storage
MalwareValak

Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.

T1027.011
Fileless Storage
MalwarePillowmint

Pillowmint has stored a compressed payload in the Registry key HKLM\SOFTWARE\Microsoft\DRM.

T1027.011
Fileless Storage
MalwareSysUpdate

SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1027.011
Fileless Storage
MalwareCHOPSTICK

CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.

T1027.011
Fileless Storage
MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1027.011
Fileless Storage
MalwareShadowPad

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1027.011
Fileless Storage
MalwareQakBot

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1027.011
Fileless Storage
MalwareGelsemium

Gelsemium can store its components in the Registry.

T1027.012
LNK Icon Smuggling
MalwareTONESHELL

TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1027.013
Encrypted/Encoded File
MalwareTrickBot

TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files.

T1027.013
Encrypted/Encoded File
MalwareBLINDINGCAN

BLINDINGCAN has obfuscated code using Base64 encoding.

T1027.013
Encrypted/Encoded File
MalwareNinja

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.