Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping. |
| T1005 Data from Local System |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from local systems. |
| T1007 System Service Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1018 Remote System Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER typically use |
| T1027.001 Binary Padding |
GroupBRONZE BUTLER | BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1027.003 Steganography |
GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1036 Masquerading |
GroupBRONZE BUTLER | BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| T1036.002 Right-to-Left Override |
GroupBRONZE BUTLER | BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupBRONZE BUTLER | BRONZE BUTLER has given malware the same name as an existing file on the file share server to cause users to unwittingly launch and install the malware on additional systems. |
| T1039 Data from Network Shared Drive |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from file shares. |
| T1053.002 At |
GroupBRONZE BUTLER | BRONZE BUTLER has used at to register a scheduled task to execute malware during lateral movement. |
| T1053.005 Scheduled Task |
GroupBRONZE BUTLER | BRONZE BUTLER has used schtasks to register a scheduled task to execute malware during lateral movement. |
| T1059.001 PowerShell |
GroupBRONZE BUTLER | BRONZE BUTLER has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
GroupBRONZE BUTLER | BRONZE BUTLER has used batch scripts and the command-line interface for execution. |
| T1059.005 Visual Basic |
GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| T1059.006 Python |
GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| T1070.004 File Deletion |
GroupBRONZE BUTLER | The BRONZE BUTLER uploader or malware the uploader uses |
| T1071.001 Web Protocols |
GroupBRONZE BUTLER | BRONZE BUTLER malware has used HTTP for C2. |
| T1080 Taint Shared Content |
GroupBRONZE BUTLER | BRONZE BUTLER has placed malware on file shares and given it the same name as legitimate documents on the share. |
| T1083 File and Directory Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal. |
| T1087.002 Domain Account |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1102.001 Dead Drop Resolver |
GroupBRONZE BUTLER | BRONZE BUTLER's MSGET downloader uses a dead drop resolver to access malicious payloads. |
| T1105 Ingress Tool Transfer |
GroupBRONZE BUTLER | BRONZE BUTLER has used various tools to download files, including DGet (a similar tool to wget). |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1124 System Time Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1132.001 Standard Encoding |
GroupBRONZE BUTLER | Several BRONZE BUTLER tools encode data with base64 when posting it to a C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBRONZE BUTLER | BRONZE BUTLER downloads encoded payloads and decodes them on the victim. |
| T1189 Drive-by Compromise |
GroupBRONZE BUTLER | BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks. |
| T1203 Exploitation for Client Execution |
GroupBRONZE BUTLER | BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution. |
| T1204.002 Malicious File |
GroupBRONZE BUTLER | BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1518 Software Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupBRONZE BUTLER | BRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence. |
| T1548.002 Bypass User Account Control |
GroupBRONZE BUTLER | BRONZE BUTLER has used a Windows 10 specific tool and xxmm to bypass UAC for privilege escalation. |
| T1550.003 Pass the Ticket |
GroupBRONZE BUTLER | BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access. |
| T1560.001 Archive via Utility |
GroupBRONZE BUTLER | BRONZE BUTLER has compressed data into password-protected RAR archives prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupBRONZE BUTLER | BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims. |
| T1573.001 Symmetric Cryptography |
GroupBRONZE BUTLER | BRONZE BUTLER has used RC4 encryption (for Datper malware) and AES (for xxmm malware) to obfuscate HTTP traffic. BRONZE BUTLER has also used a tool called RarStar that encodes data with a custom XOR algorithm when posting it to a C2 server. |
| T1574.001 DLL |
GroupBRONZE BUTLER | BRONZE BUTLER has used legitimate applications to side-load malicious DLLs. |
| T1588.002 Tool |
GroupBRONZE BUTLER | BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor. |
| T1685 Disable or Modify Tools |
GroupBRONZE BUTLER | BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.