ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0001×

27 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to gather various local system information.

T1016
System Network Configuration Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to find the public IP address of a compromised system.

T1020
Automated Exfiltration
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which was automatically sent back to the adversary's C2.

T1027.010
Command Obfuscation
CampaignFrankenstein

During Frankenstein, the threat actors ran encoded commands from the command line.

T1033
System Owner/User Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.

T1036.004
Masquerade Task or Service
CampaignFrankenstein

During Frankenstein, the threat actors named a malicious scheduled task "WinUpdate" for persistence.

T1041
Exfiltration Over C2 Channel
CampaignFrankenstein

During Frankenstein, the threat actors collected information via Empire, which sent the data back to the adversary's C2.

T1047
Windows Management Instrumentation
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

T1053.005
Scheduled Task
CampaignFrankenstein

During Frankenstein, the threat actors established persistence through a scheduled task using the command: `/Create /F /SC DAILY /ST 09:00 /TN WinUpdate /TR`, named "WinUpdate"

T1057
Process Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

T1059.001
PowerShell
CampaignFrankenstein

During Frankenstein, the threat actors used PowerShell to run a series of Base64-encoded commands that acted as a stager and enumerated hosts.

T1059.003
Windows Command Shell
CampaignFrankenstein

During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate", as well as other encoded commands from the command-line

T1059.005
Visual Basic
CampaignFrankenstein

During Frankenstein, the threat actors used Word documents that prompted the victim to enable macros and run a Visual Basic script.

T1071.001
Web Protocols
CampaignFrankenstein

During Frankenstein, the threat actors used HTTP GET requests for C2.

T1082
System Information Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain the compromised machine's name.

T1105
Ingress Tool Transfer
CampaignFrankenstein

During Frankenstein, the threat actors downloaded files and tools onto a victim machine.

T1119
Automated Collection
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information.

T1127.001
MSBuild
CampaignFrankenstein

During Frankenstein, the threat actors used MSbuild to execute an actor-created file.

T1140
Deobfuscate/Decode Files or Information
CampaignFrankenstein

During Frankenstein, the threat actors deobfuscated Base64-encoded commands following the execution of a malicious script, which revealed a small script designed to obtain an additional payload.

T1203
Exploitation for Client Execution
CampaignFrankenstein

During Frankenstein, the threat actors exploited CVE-2017-11882 to execute code on the victim's machine.

T1204.002
Malicious File
CampaignFrankenstein

During Frankenstein, the threat actors relied on a victim to enable macros within a malicious Microsoft Word document likely sent via email.

T1221
Template Injection
CampaignFrankenstein

During Frankenstein, the threat actors used trojanized documents that retrieved remote templates from an adversary-controlled website.

T1497.001
System Checks
CampaignFrankenstein

During Frankenstein, the threat actors used a script that ran WMI queries to check if a VM or sandbox was running, including VMWare and Virtualbox. The script would also call WMI to determine the number of cores allocated to the system; if less than two the script would stop execution.

T1518.001
Security Software Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system.

T1566.001
Spearphishing Attachment
CampaignFrankenstein

During Frankenstein, the threat actors likely used spearphishing emails to send malicious Microsoft Word documents.

T1573.001
Symmetric Cryptography
CampaignFrankenstein

During Frankenstein, the threat actors communicated with C2 via an encrypted RC4 byte stream and AES-CBC.

T1588.002
Tool
CampaignFrankenstein

For Frankenstein, the threat actors obtained and used Empire.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.