Real-world descriptions of how a group, tool or campaign used a technique.
34 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupTA505 | TA505 has used UPX to obscure malicious code. |
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
GroupTA505 | TA505 has password-protected malicious Word documents. |
| T1055.001 Dynamic-link Library Injection |
GroupTA505 | TA505 has been seen injecting a DLL into winword.exe. |
| T1059.001 PowerShell |
GroupTA505 | TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1059.003 Windows Command Shell |
GroupTA505 | TA505 has executed commands using |
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1059.007 JavaScript |
GroupTA505 | TA505 has used JavaScript for code execution. |
| T1069 Permission Groups Discovery |
GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1071.001 Web Protocols |
GroupTA505 | TA505 has used HTTP to communicate with C2 nodes. |
| T1078.002 Domain Accounts |
GroupTA505 | TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1087.003 Email Account |
GroupTA505 | TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server. |
| T1105 Ingress Tool Transfer |
GroupTA505 | TA505 has downloaded additional malware to execute on victim systems. |
| T1106 Native API |
GroupTA505 | TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1112 Modify Registry |
GroupTA505 | TA505 has used malware to disable Windows Defender through modification of the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTA505 | TA505 has decrypted packed DLLs with an XOR key. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1218.011 Rundll32 |
GroupTA505 | TA505 has leveraged |
| T1486 Data Encrypted for Impact |
GroupTA505 | TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment. |
| T1552.001 Credentials In Files |
GroupTA505 | TA505 has used malware to gather credentials from FTP clients and Outlook. |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1553.005 Mark-of-the-Web Bypass |
GroupTA505 | TA505 has used .iso files to deploy malicious .lnk files. |
| T1555.003 Credentials from Web Browsers |
GroupTA505 | TA505 has used malware to gather credentials from Internet Explorer. |
| T1559.002 Dynamic Data Exchange |
GroupTA505 | TA505 has leveraged malicious Word documents that abused DDE. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
| T1568.001 Fast Flux DNS |
GroupTA505 | TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs. |
| T1583.001 Domains |
GroupTA505 | TA505 has registered domains to impersonate services such as Dropbox to distribute malware. |
| T1588.001 Malware |
GroupTA505 | TA505 has used malware such as Azorult and Cobalt Strike in their operations. |
| T1588.002 Tool |
GroupTA505 | TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit. |
| T1608.001 Upload Malware |
GroupTA505 | TA505 has staged malware on actor-controlled domains. |
| T1685 Disable or Modify Tools |
GroupTA505 | TA505 has used malware to disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.