Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareCobalt Strike | Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic. |
| T1003.001 LSASS Memory |
MalwareCobalt Strike | Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes. |
| T1003.002 Security Account Manager |
MalwareCobalt Strike | Cobalt Strike can recover hashed passwords. |
| T1005 Data from Local System |
MalwareCobalt Strike | Cobalt Strike can collect data from a local system. |
| T1007 System Service Discovery |
MalwareCobalt Strike | Cobalt Strike can enumerate services on compromised hosts. |
| T1012 Query Registry |
MalwareCobalt Strike | Cobalt Strike can query |
| T1016 System Network Configuration Discovery |
MalwareCobalt Strike | Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers. |
| T1018 Remote System Discovery |
MalwareCobalt Strike | Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network. |
| T1021.001 Remote Desktop Protocol |
MalwareCobalt Strike | Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel. |
| T1021.002 SMB/Windows Admin Shares |
MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1021.003 Distributed Component Object Model |
MalwareCobalt Strike | Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution. |
| T1021.004 SSH |
MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| T1021.006 Windows Remote Management |
MalwareCobalt Strike | Cobalt Strike can use |
| T1027 Obfuscated Files or Information |
MalwareCobalt Strike | Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata. |
| T1027.005 Indicator Removal from Tools |
MalwareCobalt Strike | Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods. |
| T1029 Scheduled Transfer |
MalwareCobalt Strike | Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval. |
| T1030 Data Transfer Size Limits |
MalwareCobalt Strike | Cobalt Strike will break large data sets into smaller chunks for exfiltration. |
| T1046 Network Service Discovery |
MalwareCobalt Strike | Cobalt Strike can perform port scans from an infected host. |
| T1047 Windows Management Instrumentation |
MalwareCobalt Strike | Cobalt Strike can use WMI to deliver a payload to a remote host. |
| T1049 System Network Connections Discovery |
MalwareCobalt Strike | Cobalt Strike can produce a sessions report from compromised hosts. |
| T1055 Process Injection |
MalwareCobalt Strike | Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary. |
| T1055.001 Dynamic-link Library Injection |
MalwareCobalt Strike | Cobalt Strike has the ability to load DLLs via reflective injection. |
| T1055.012 Process Hollowing |
MalwareCobalt Strike | Cobalt Strike can use process hollowing for execution. |
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1059.001 PowerShell |
MalwareCobalt Strike | Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution. |
| T1059.003 Windows Command Shell |
MalwareCobalt Strike | Cobalt Strike uses a command-line interface to interact with systems. |
| T1059.005 Visual Basic |
MalwareCobalt Strike | Cobalt Strike can use VBA to perform execution. |
| T1059.006 Python |
MalwareCobalt Strike | Cobalt Strike can use Python to perform execution. |
| T1059.007 JavaScript |
MalwareCobalt Strike | The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1069.001 Local Groups |
MalwareCobalt Strike | Cobalt Strike can use |
| T1069.002 Domain Groups |
MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| T1070.006 Timestomp |
MalwareCobalt Strike | Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in. |
| T1071.001 Web Protocols |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.004 DNS |
MalwareCobalt Strike | Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports. |
| T1078.002 Domain Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| T1078.003 Local Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account. |
| T1083 File and Directory Discovery |
MalwareCobalt Strike | Cobalt Strike can explore files on a compromised system. |
| T1087.002 Domain Account |
MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| T1090.001 Internal Proxy |
MalwareCobalt Strike | Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access. |
| T1090.004 Domain Fronting |
MalwareCobalt Strike | Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting. |
| T1095 Non-Application Layer Protocol |
MalwareCobalt Strike | Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareCobalt Strike | Cobalt Strike can deliver additional payloads to victim machines. |
| T1106 Native API |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of running shell commands without |
| T1112 Modify Registry |
MalwareCobalt Strike | Cobalt Strike can modify Registry values within |
| T1113 Screen Capture |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of capturing screenshots. |
| T1132.001 Standard Encoding |
MalwareCobalt Strike | Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic. |
| T1134.001 Token Impersonation/Theft |
MalwareCobalt Strike | Cobalt Strike can steal access tokens from exiting processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.