Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareRogueRobin | The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`. |
| T1027.010 Command Obfuscation |
MalwareSQLRat | SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters. |
| T1027.010 Command Obfuscation |
MalwareSibot | Sibot has obfuscated scripts used in execution. |
| T1027.010 Command Obfuscation |
MalwareBackConfig | BackConfig has used compressed and decimal encoded VBS scripts. |
| T1027.010 Command Obfuscation |
MalwarePHASEJAM | PHASEJAM has encoded commands with Base64. |
| T1027.010 Command Obfuscation |
MalwarePoetRAT | PoetRAT has `pyminifier` to obfuscate scripts. |
| T1027.010 Command Obfuscation |
MalwarePowerPunch | PowerPunch can use Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| T1027.010 Command Obfuscation |
MalwareIceApple | IceApple can use Base64 and "junk" JavaScript code to obfuscate information. |
| T1027.010 Command Obfuscation |
MalwareKOCTOPUS | KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1027.010 Command Obfuscation |
MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| T1027.010 Command Obfuscation |
MalwareQakBot | QakBot can use obfuscated and encoded scripts. |
| T1027.010 Command Obfuscation |
MalwareCookieMiner | CookieMiner has used base64 encoding to obfuscate scripts on the system. |
| T1027.010 Command Obfuscation |
MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| T1027.010 Command Obfuscation |
MalwareLoudMiner | LoudMiner has obfuscated various scripts. |
| T1027.010 Command Obfuscation |
MalwareXORIndex Loader | XORIndex Loader has obfuscated strings using ASCII buffers and TextDecoder. |
| T1027.010 Command Obfuscation |
ToolPowerSploit | PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads. |
| T1027.010 Command Obfuscation |
ToolEmpire | Empire has the ability to obfuscate commands using |
| T1027.011 Fileless Storage |
MalwarePikabot | Some versions of Pikabot build the final PE payload in memory to avoid writing contents to disk on the executing machine. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.011 Fileless Storage |
MalwareExaramel for Windows | Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| T1027.011 Fileless Storage |
MalwareThreatNeedle | ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`. |
| T1027.011 Fileless Storage |
MalwareNETWIRE | NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1027.011 Fileless Storage |
MalwareTinyTurla | TinyTurla can save its configuration parameters in the Registry. |
| T1027.011 Fileless Storage |
MalwarePolyglotDuke | PolyglotDuke can store encrypted JSON configuration files in the Registry. |
| T1027.011 Fileless Storage |
MalwareRegDuke | RegDuke can store its encryption key in the Registry. |
| T1027.011 Fileless Storage |
MalwareVolgmer | Volgmer stores an encoded configuration file in |
| T1027.011 Fileless Storage |
MalwareDarkWatchman | DarkWatchman can store configuration strings, keylogger, and output of components in the Registry. |
| T1027.011 Fileless Storage |
MalwareChaes | Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| T1027.011 Fileless Storage |
MalwareTYPEFRAME | TYPEFRAME can install and store encrypted configuration data under the Registry key |
| T1027.011 Fileless Storage |
MalwareQUADAGENT | QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as `HKCU\Office365DCOMCheck`) in the `HKCU` hive. |
| T1027.011 Fileless Storage |
MalwareUroburos | Uroburos can store configuration information for the kernel driver and kernel driver loader components in an encrypted blob typically found at `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds.` |
| T1027.011 Fileless Storage |
MalwarePipeMon | PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`. |
| T1027.011 Fileless Storage |
MalwareMosquito | Mosquito stores configuration values under the Registry key |
| T1027.011 Fileless Storage |
MalwareGrandoreiro | Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| T1027.011 Fileless Storage |
MalwareSibot | Sibot has installed a second-stage script in the |
| T1027.011 Fileless Storage |
MalwareREvil | REvil can save encryption parameters and system information in the Registry. |
| T1027.011 Fileless Storage |
MalwareValak | Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1027.011 Fileless Storage |
MalwarePillowmint | Pillowmint has stored a compressed payload in the Registry key |
| T1027.011 Fileless Storage |
MalwareSysUpdate | SysUpdate can store its encoded configuration file within |
| T1027.011 Fileless Storage |
MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1027.011 Fileless Storage |
MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| T1027.011 Fileless Storage |
MalwareShadowPad | ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1027.011 Fileless Storage |
MalwareQakBot | QakBot can store its configuration information in a randomly named subkey under |
| T1027.011 Fileless Storage |
MalwareGelsemium | Gelsemium can store its components in the Registry. |
| T1027.012 LNK Icon Smuggling |
MalwareTONESHELL | TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.013 Encrypted/Encoded File |
MalwareTrickBot | TrickBot uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. |
| T1027.013 Encrypted/Encoded File |
MalwareBLINDINGCAN | BLINDINGCAN has obfuscated code using Base64 encoding. |
| T1027.013 Encrypted/Encoded File |
MalwareNinja | The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.