ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0154×

73 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1003.001
LSASS Memory
MalwareCobalt Strike

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

T1003.002
Security Account Manager
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

T1005
Data from Local System
MalwareCobalt Strike

Cobalt Strike can collect data from a local system.

T1007
System Service Discovery
MalwareCobalt Strike

Cobalt Strike can enumerate services on compromised hosts.

T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1016
System Network Configuration Discovery
MalwareCobalt Strike

Cobalt Strike can determine the NetBios name and the IP addresses of targets machines including domain controllers.

T1018
Remote System Discovery
MalwareCobalt Strike

Cobalt Strike uses the native Windows Network Enumeration APIs to interrogate and discover targets in a Windows Active Directory network.

T1021.001
Remote Desktop Protocol
MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1021.002
SMB/Windows Admin Shares
MalwareCobalt Strike

Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement.

T1021.003
Distributed Component Object Model
MalwareCobalt Strike

Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution.

T1021.004
SSH
MalwareCobalt Strike

Cobalt Strike can SSH to a remote service.

T1021.006
Windows Remote Management
MalwareCobalt Strike

Cobalt Strike can use WinRM to execute a payload on a remote host.

T1027
Obfuscated Files or Information
MalwareCobalt Strike

Cobalt Strike can hash functions to obfuscate calls to the Windows API and use a public/private key pair to encrypt Beacon session metadata.

T1027.005
Indicator Removal from Tools
MalwareCobalt Strike

Cobalt Strike includes a capability to modify the Beacon payload to eliminate known signatures or unpacking methods.

T1029
Scheduled Transfer
MalwareCobalt Strike

Cobalt Strike can set its Beacon payload to reach out to the C2 server on an arbitrary and random interval.

T1030
Data Transfer Size Limits
MalwareCobalt Strike

Cobalt Strike will break large data sets into smaller chunks for exfiltration.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1049
System Network Connections Discovery
MalwareCobalt Strike

Cobalt Strike can produce a sessions report from compromised hosts.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1055.001
Dynamic-link Library Injection
MalwareCobalt Strike

Cobalt Strike has the ability to load DLLs via reflective injection.

T1055.012
Process Hollowing
MalwareCobalt Strike

Cobalt Strike can use process hollowing for execution.

T1056.001
Keylogging
MalwareCobalt Strike

Cobalt Strike can track key presses with a keylogger module.

T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1059.001
PowerShell
MalwareCobalt Strike

Cobalt Strike can execute a payload on a remote host with PowerShell. This technique does not write any data to disk. Cobalt Strike can also use PowerSploit and other scripting frameworks to perform execution.

T1059.003
Windows Command Shell
MalwareCobalt Strike

Cobalt Strike uses a command-line interface to interact with systems.

T1059.005
Visual Basic
MalwareCobalt Strike

Cobalt Strike can use VBA to perform execution.

T1059.006
Python
MalwareCobalt Strike

Cobalt Strike can use Python to perform execution.

T1059.007
JavaScript
MalwareCobalt Strike

The Cobalt Strike System Profiler can use JavaScript to perform reconnaissance actions.

T1068
Exploitation for Privilege Escalation
MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

T1069.001
Local Groups
MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

T1069.002
Domain Groups
MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

T1070.006
Timestomp
MalwareCobalt Strike

Cobalt Strike can timestomp any files or payloads placed on a target machine to help them blend in.

T1071.001
Web Protocols
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in HTTP or HTTPS. All protocols use their standard assigned ports.

T1071.002
File Transfer Protocols
MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1071.004
DNS
MalwareCobalt Strike

Cobalt Strike can use a custom command and control protocol that can be encapsulated in DNS. All protocols use their standard assigned ports.

T1078.002
Domain Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account.

T1078.003
Local Accounts
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

T1083
File and Directory Discovery
MalwareCobalt Strike

Cobalt Strike can explore files on a compromised system.

T1087.002
Domain Account
MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

T1090.001
Internal Proxy
MalwareCobalt Strike

Cobalt Strike can be configured to have commands relayed over a peer-to-peer network of infected hosts. This can be used to limit the number of egress points, or provide access to a host without direct internet access.

T1090.004
Domain Fronting
MalwareCobalt Strike

Cobalt Strike has the ability to accept a value for HTTP Host Header to enable domain fronting.

T1095
Non-Application Layer Protocol
MalwareCobalt Strike

Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications.

T1105
Ingress Tool Transfer
MalwareCobalt Strike

Cobalt Strike can deliver additional payloads to victim machines.

T1106
Native API
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of running shell commands without cmd.exe and PowerShell commands without powershell.exe Cobalt Strike can also use `CreateThreadpoolWait`, `SetThreadpoolWait`, and `MessageBoxA` for sandbox evasion and execution of embedded payloads in memory.

T1112
Modify Registry
MalwareCobalt Strike

Cobalt Strike can modify Registry values within HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to enable the execution of additional code.

T1113
Screen Capture
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of capturing screenshots.

T1132.001
Standard Encoding
MalwareCobalt Strike

Cobalt Strike can use Base64, URL-safe Base64, or NetBIOS encoding in its C2 traffic.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.