Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on network interfaces, including the MAC address. |
| T1020 Automated Exfiltration |
GroupSidewinder | Sidewinder has configured tools to automatically send collected files to attacker controlled servers. |
| T1027.010 Command Obfuscation |
GroupSidewinder | Sidewinder has used base64 encoding for scripts. |
| T1027.013 Encrypted/Encoded File |
GroupSidewinder | Sidewinder has used base64 encoding and ECDH-P256 encryption for payloads. |
| T1033 System Owner/User Discovery |
GroupSidewinder | Sidewinder has used tools to identify the user of a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSidewinder | Sidewinder has named malicious files |
| T1057 Process Discovery |
GroupSidewinder | Sidewinder has used tools to identify running processes on the victim's machine. |
| T1059.001 PowerShell |
GroupSidewinder | Sidewinder has used PowerShell to drop and execute malware loaders. |
| T1059.005 Visual Basic |
GroupSidewinder | Sidewinder has used VBScript to drop and execute malware loaders. |
| T1059.007 JavaScript |
GroupSidewinder | Sidewinder has used JavaScript to drop and execute malware loaders. |
| T1071.001 Web Protocols |
GroupSidewinder | Sidewinder has used HTTP in C2 communications. |
| T1074.001 Local Data Staging |
GroupSidewinder | Sidewinder has collected stolen files in a temporary folder in preparation for exfiltration. |
| T1082 System Information Discovery |
GroupSidewinder | Sidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host. |
| T1083 File and Directory Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on files and directories. |
| T1105 Ingress Tool Transfer |
GroupSidewinder | Sidewinder has used LNK files to download remote files to the victim's network. |
| T1119 Automated Collection |
GroupSidewinder | Sidewinder has used tools to automatically collect system and network configuration information. |
| T1124 System Time Discovery |
GroupSidewinder | Sidewinder has used tools to obtain the current system time. |
| T1203 Exploitation for Client Execution |
GroupSidewinder | Sidewinder has exploited vulnerabilities to gain execution including CVE-2017-11882 and CVE-2020-0674. |
| T1204.001 Malicious Link |
GroupSidewinder | Sidewinder has lured targets to click on malicious links to gain execution in the target environment. |
| T1204.002 Malicious File |
GroupSidewinder | Sidewinder has lured targets to click on malicious files to gain execution in the target environment. |
| T1218.005 Mshta |
GroupSidewinder | Sidewinder has used |
| T1518 Software Discovery |
GroupSidewinder | Sidewinder has used tools to enumerate software installed on an infected host. |
| T1518.001 Security Software Discovery |
GroupSidewinder | Sidewinder has used the Windows service |
| T1547.001 Registry Run Keys / Startup Folder |
GroupSidewinder | Sidewinder has added paths to executables in the Registry to establish persistence. |
| T1559.002 Dynamic Data Exchange |
GroupSidewinder | Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer. |
| T1566.001 Spearphishing Attachment |
GroupSidewinder | Sidewinder has sent e-mails with malicious attachments often crafted for specific targets. |
| T1566.002 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links often crafted for specific targets. |
| T1574.001 DLL |
GroupSidewinder | Sidewinder has used DLL side-loading to drop and execute malicious payloads including the hijacking of the legitimate Windows application file rekeywiz.exe. |
| T1598.002 Spearphishing Attachment |
GroupSidewinder | Sidewinder has sent e-mails with malicious attachments that lead victims to credential harvesting websites. |
| T1598.003 Spearphishing Link |
GroupSidewinder | Sidewinder has sent e-mails with malicious links to credential harvesting websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.