Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupTropic Trooper | Tropic Trooper has used scripts to collect the host's network topology. |
| T1020 Automated Exfiltration |
GroupTropic Trooper | Tropic Trooper has used a copy function to automatically exfiltrate sensitive data from air-gapped systems using USB storage. |
| T1027.003 Steganography |
GroupTropic Trooper | Tropic Trooper has used JPG files with encrypted payloads to mask their backdoor routines and evade detection. |
| T1027.013 Encrypted/Encoded File |
GroupTropic Trooper | Tropic Trooper has encrypted configuration files. |
| T1033 System Owner/User Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTropic Trooper | Tropic Trooper has hidden payloads in Flash directories and fake installer files. |
| T1046 Network Service Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1049 System Network Connections Discovery |
GroupTropic Trooper | Tropic Trooper has tested if the localhost network is available and other connection capability on an infected system using command scripts. |
| T1052.001 Exfiltration over USB |
GroupTropic Trooper | Tropic Trooper has exfiltrated data using USB storage devices. |
| T1055.001 Dynamic-link Library Injection |
GroupTropic Trooper | Tropic Trooper has injected a DLL backdoor into dllhost.exe and svchost.exe. |
| T1057 Process Discovery |
GroupTropic Trooper | Tropic Trooper is capable of enumerating the running processes on the system using |
| T1059.003 Windows Command Shell |
GroupTropic Trooper | Tropic Trooper has used Windows command scripts. |
| T1070.004 File Deletion |
GroupTropic Trooper | Tropic Trooper has deleted dropper files on an infected system using command scripts. |
| T1071.001 Web Protocols |
GroupTropic Trooper | Tropic Trooper has used HTTP in communication with the C2. |
| T1071.004 DNS |
GroupTropic Trooper | Tropic Trooper's backdoor has communicated to the C2 over the DNS protocol. |
| T1078.003 Local Accounts |
GroupTropic Trooper | Tropic Trooper has used known administrator account credentials to execute the backdoor directly. |
| T1082 System Information Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s OS version. |
| T1083 File and Directory Discovery |
GroupTropic Trooper | Tropic Trooper has monitored files' modified time. |
| T1091 Replication Through Removable Media |
GroupTropic Trooper | Tropic Trooper has attempted to transfer USBferry from an infected USB device by copying an Autorun function to the target machine. |
| T1105 Ingress Tool Transfer |
GroupTropic Trooper | Tropic Trooper has used a delivered trojan to download additional files. |
| T1106 Native API |
GroupTropic Trooper | Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl. |
| T1119 Automated Collection |
GroupTropic Trooper | Tropic Trooper has collected information automatically using the adversary's USBferry attack. |
| T1132.001 Standard Encoding |
GroupTropic Trooper | Tropic Trooper has used base64 encoding to hide command strings delivered from the C2. |
| T1135 Network Share Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1140 Deobfuscate/Decode Files or Information |
GroupTropic Trooper | Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload. |
| T1203 Exploitation for Client Execution |
GroupTropic Trooper | Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158. |
| T1204.002 Malicious File |
GroupTropic Trooper | Tropic Trooper has lured victims into executing malware via malicious e-mail attachments. |
| T1221 Template Injection |
GroupTropic Trooper | Tropic Trooper delivered malicious documents with the XLSX extension, typically used by OpenXML documents, but the file itself was actually an OLE (XLS) document. |
| T1505.003 Web Shell |
GroupTropic Trooper | Tropic Trooper has started a web service in the target host and wait for the adversary to connect, acting as a web shell. |
| T1518 Software Discovery |
GroupTropic Trooper | Tropic Trooper's backdoor could list the infected system's installed software. |
| T1518.001 Security Software Discovery |
GroupTropic Trooper | Tropic Trooper can search for anti-virus software running on the system. |
| T1543.003 Windows Service |
GroupTropic Trooper | Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTropic Trooper | Tropic Trooper has created shortcuts in the Startup folder to establish persistence. |
| T1547.004 Winlogon Helper DLL |
GroupTropic Trooper | Tropic Trooper has created the Registry key |
| T1564.001 Hidden Files and Directories |
GroupTropic Trooper | Tropic Trooper has created a hidden directory under |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
| T1573 Encrypted Channel |
GroupTropic Trooper | Tropic Trooper has encrypted traffic with the C2 to prevent network detection. |
| T1573.002 Asymmetric Cryptography |
GroupTropic Trooper | Tropic Trooper has used SSL to connect to C2 servers. |
| T1574.001 DLL |
GroupTropic Trooper | Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools. |
| T1680 Local Storage Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s system volume information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.