ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0100×

22 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupInception

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1027.013
Encrypted/Encoded File
GroupInception

Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption.

T1057
Process Discovery
GroupInception

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1059.001
PowerShell
GroupInception

Inception has used PowerShell to execute malicious commands and payloads.

T1059.005
Visual Basic
GroupInception

Inception has used VBScript to execute malicious commands and payloads.

T1069.002
Domain Groups
GroupInception

Inception has used specific malware modules to gather domain membership.

T1071.001
Web Protocols
GroupInception

Inception has used HTTP, HTTPS, and WebDav in network communications.

T1082
System Information Discovery
GroupInception

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.

T1083
File and Directory Discovery
GroupInception

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.

T1090.003
Multi-hop Proxy
GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1102
Web Service
GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1203
Exploitation for Client Execution
GroupInception

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1218.005
Mshta
GroupInception

Inception has used malicious HTA files to drop and execute malware.

T1218.010
Regsvr32
GroupInception

Inception has ensured persistence at system boot by setting the value regsvr32 %path%\ctfmonrn.dll /s.

T1221
Template Injection
GroupInception

Inception has used decoy documents to load malicious remote payloads via HTTP.

T1518
Software Discovery
GroupInception

Inception has enumerated installed software on compromised systems.

T1547.001
Registry Run Keys / Startup Folder
GroupInception

Inception has maintained persistence by modifying Registry run key value
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.

T1555.003
Credentials from Web Browsers
GroupInception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

T1573.001
Symmetric Cryptography
GroupInception

Inception has encrypted network communications with AES.

T1588.002
Tool
GroupInception

Inception has obtained and used open-source tools such as LaZagne.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.