Real-world descriptions of how a group, tool or campaign used a technique.
35 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareAttor | Attor can obtain application window titles and then determines which windows to perform Screen Capture on. |
| T1012 Query Registry |
MalwareAttor | Attor has opened the registry and performed query searches. |
| T1020 Automated Exfiltration |
MalwareAttor | Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| T1027.013 Encrypted/Encoded File |
MalwareAttor | Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA. |
| T1036.004 Masquerade Task or Service |
MalwareAttor | Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate). |
| T1037.001 Logon Script (Windows) |
MalwareAttor | Attor's dispatcher can establish persistence via adding a Registry key with a logon script |
| T1041 Exfiltration Over C2 Channel |
MalwareAttor | Attor has exfiltrated data over the C2 channel. |
| T1053.005 Scheduled Task |
MalwareAttor | Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon. |
| T1055 Process Injection |
MalwareAttor | Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection. |
| T1055.004 Asynchronous Procedure Call |
MalwareAttor | Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API. |
| T1056.001 Keylogging |
MalwareAttor | One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process. |
| T1070.004 File Deletion |
MalwareAttor | Attor’s plugin deletes the collected files and log files after exfiltration. |
| T1070.006 Timestomp |
MalwareAttor | Attor has manipulated the time of last access to files and registry keys after they have been created or modified. |
| T1071.002 File Transfer Protocols |
MalwareAttor | Attor has used FTP protocol for C2 communication. |
| T1074.001 Local Data Staging |
MalwareAttor | Attor has staged collected data in a central upload directory prior to exfiltration. |
| T1083 File and Directory Discovery |
MalwareAttor | Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files. |
| T1090.003 Multi-hop Proxy |
MalwareAttor | |
| T1105 Ingress Tool Transfer |
MalwareAttor | Attor can download additional plugins, updates and other files. |
| T1106 Native API |
MalwareAttor | Attor's dispatcher has used CreateProcessW API for execution. |
| T1112 Modify Registry |
MalwareAttor | Attor's dispatcher can modify the Run registry key. |
| T1113 Screen Capture |
MalwareAttor | Attor's has a plugin that captures screenshots of the target applications. |
| T1115 Clipboard Data |
MalwareAttor | Attor has a plugin that collects data stored in the Windows clipboard by using the OpenClipboard and GetClipboardData APIs. |
| T1119 Automated Collection |
MalwareAttor | Attor has automatically collected data about the compromised system. |
| T1120 Peripheral Device Discovery |
MalwareAttor | Attor has a plugin that collects information about inserted storage devices, modems, and phone devices. |
| T1123 Audio Capture |
MalwareAttor | Attor's has a plugin that is capable of recording audio using available input sound devices. |
| T1129 Shared Modules |
MalwareAttor | Attor's dispatcher can execute additional plugins by loading the respective DLLs. |
| T1218.011 Rundll32 |
MalwareAttor | Attor's installer plugin can schedule rundll32.exe to load the dispatcher. |
| T1497.001 System Checks |
MalwareAttor | Attor can detect whether it is executed in some virtualized or emulated environment by searching for specific artifacts, such as communication with I/O ports and using VM-specific instructions. |
| T1543.003 Windows Service |
MalwareAttor | Attor's dispatcher can establish persistence by registering a new service. |
| T1560.003 Archive via Custom Method |
MalwareAttor | Attor encrypts collected data with a custom implementation of Blowfish and RSA ciphers. |
| T1564.001 Hidden Files and Directories |
MalwareAttor | Attor can set attributes of log files and directories to HIDDEN, SYSTEM, ARCHIVE, or a combination of those. |
| T1569.002 Service Execution |
MalwareAttor | Attor's dispatcher can be executed as a service. |
| T1573.001 Symmetric Cryptography |
MalwareAttor | Attor has encrypted data symmetrically using a randomly generated Blowfish (OFB) key which is encrypted with a public RSA key. |
| T1573.002 Asymmetric Cryptography |
MalwareAttor | Attor's Blowfish key is encrypted with a public RSA key. |
| T1680 Local Storage Discovery |
MalwareAttor | Attor monitors the free disk space on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.