Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.007 Proc Filesystem |
PACEMAKER has the ability to extract credentials from OS memory. |
| T1055.008 Ptrace System Calls |
PACEMAKER can use PTRACE to attach to a targeted process to read process memory. |
| T1059.004 Unix Shell |
PACEMAKER can use a simple bash script for execution. |
| T1074.001 Local Data Staging |
PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`. |
| T1083 File and Directory Discovery |
PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line. |
| T1119 Automated Collection |
PACEMAKER can enter a loop to read `/proc/` entries every 2 seconds in order to read a target application's memory. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.