Real-world descriptions of how a group, tool or campaign used a technique.
19 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupWindshift | Windshift has used string encoding with floating point calculations. |
| T1033 System Owner/User Discovery |
GroupWindshift | Windshift has used malware to identify the username on a compromised host. |
| T1036 Masquerading |
GroupWindshift | Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1036.001 Invalid Code Signature |
GroupWindshift | Windshift has used revoked certificates to sign malware. |
| T1047 Windows Management Instrumentation |
GroupWindshift | Windshift has used WMI to collect information about target machines. |
| T1057 Process Discovery |
GroupWindshift | Windshift has used malware to enumerate active processes. |
| T1059.005 Visual Basic |
GroupWindshift | Windshift has used Visual Basic 6 (VB6) payloads. |
| T1071.001 Web Protocols |
GroupWindshift | Windshift has used tools that communicate with C2 over HTTP. |
| T1082 System Information Discovery |
GroupWindshift | Windshift has used malware to identify the computer name of a compromised host. |
| T1105 Ingress Tool Transfer |
GroupWindshift | Windshift has used tools to deploy additional payloads to compromised hosts. |
| T1189 Drive-by Compromise |
GroupWindshift | Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1204.001 Malicious Link |
GroupWindshift | Windshift has used links embedded in e-mails to lure victims into executing malicious code. |
| T1204.002 Malicious File |
GroupWindshift | Windshift has used e-mail attachments to lure victims into executing malicious code. |
| T1518 Software Discovery |
GroupWindshift | Windshift has used malware to identify installed software. |
| T1518.001 Security Software Discovery |
GroupWindshift | Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWindshift | Windshift has created LNK files in the Startup folder to establish persistence. |
| T1566.001 Spearphishing Attachment |
GroupWindshift | Windshift has sent spearphishing emails with attachment to harvest credentials and deliver malware. |
| T1566.002 Spearphishing Link |
GroupWindshift | Windshift has sent spearphishing emails with links to harvest credentials and deliver malware. |
| T1566.003 Spearphishing via Service |
GroupWindshift | Windshift has used fake personas on social media to engage and target victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.