ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can establish a TCP connection as part of its initial connection to the C2.

T1095
Non-Application Layer Protocol
MalwareRegin

The Regin malware platform can use ICMP to communicate between infected computers.

T1095
Non-Application Layer Protocol
MalwareREPTILE

REPTILE can communicate using TLS over raw TCP.

T1095
Non-Application Layer Protocol
MalwareNETEAGLE

If NETEAGLE does not detect a proxy configured on the infected machine, it will send beacons via UDP/6000. Also, after retrieving a C2 IP address and Port Number, NETEAGLE will initiate a TCP connection to this socket. The ensuing connection is a plaintext C2 channel in which commands are specified by DWORDs.

T1095
Non-Application Layer Protocol
MalwareSnappyTCP

SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation.

T1095
Non-Application Layer Protocol
MalwareAnchor

Anchor has used ICMP in C2 communications.

T1095
Non-Application Layer Protocol
MalwarePlugX

PlugX can be configured to use raw TCP or UDP for command and control.

T1095
Non-Application Layer Protocol
MalwareReaver

Some Reaver variants use raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareBisonal

Bisonal has used raw sockets for network communication.

T1095
Non-Application Layer Protocol
MalwareRemsec

Remsec is capable of using ICMP, TCP, and UDP for C2.

T1095
Non-Application Layer Protocol
MalwareKEYPLUG

KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication.

T1095
Non-Application Layer Protocol
MalwareClambling

Clambling has the ability to use TCP and UDP for communication.

T1095
Non-Application Layer Protocol
MalwareTSCookie

TSCookie can use ICMP to receive information on the destination server.

T1095
Non-Application Layer Protocol
MalwarePay2Key

Pay2Key has sent its public key to the C2 server over TCP.

T1095
Non-Application Layer Protocol
MalwareRoyal

Royal establishes a TCP socket for C2 communication using the API `WSASocketW`.

T1095
Non-Application Layer Protocol
MalwareUroburos

Uroburos can communicate through custom methodologies for UDP, ICMP, and TCP that use distinct sessions to ride over the legitimate protocols.

T1095
Non-Application Layer Protocol
MalwareMetamorfo

Metamorfo has used raw TCP for C2.

T1095
Non-Application Layer Protocol
MalwareSpica

Spica can use JSON over WebSockets for C2 communications.

T1095
Non-Application Layer Protocol
MalwareBandook

Bandook has a command built in to use a raw TCP socket.

T1095
Non-Application Layer Protocol
MalwarePipeMon

The PipeMon communication module can use a custom protocol based on TLS over TCP.

T1095
Non-Application Layer Protocol
MalwareWinnti for Linux

Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications.

T1095
Non-Application Layer Protocol
Malwaregh0st RAT

gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2.

T1095
Non-Application Layer Protocol
MalwareRARSTONE

RARSTONE uses SSL to encrypt its communication with its C2 server.

T1095
Non-Application Layer Protocol
MalwareSDBbot

SDBbot has the ability to communicate with C2 with TCP over port 443.

T1095
Non-Application Layer Protocol
MalwareDerusbi

Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2.

T1095
Non-Application Layer Protocol
MalwareWellMail

WellMail can use TCP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareWINDSHIELD

WINDSHIELD C2 traffic can communicate via TCP raw sockets.

T1095
Non-Application Layer Protocol
MalwareDrovorub

Drovorub can use TCP to communicate between its agent and client modules.

T1095
Non-Application Layer Protocol
MalwareMoonWind

MoonWind completes network communication via raw sockets.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1095
Non-Application Layer Protocol
MalwareCryptoistic

Cryptoistic can use TCP in communications with C2.

T1095
Non-Application Layer Protocol
MalwareLunarMail

LunarMail can ping a specific C2 URL with the ID of a victim machine in the subdomain.

T1095
Non-Application Layer Protocol
MalwareCobalt Strike

Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareSamurai

Samurai can use a proxy module to forward TCP packets to external hosts.

T1095
Non-Application Layer Protocol
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has used a custom binary protocol over port 443 for C2 traffic.

T1095
Non-Application Layer Protocol
MalwareTaidoor

Taidoor can use TCP for C2 communications.

T1095
Non-Application Layer Protocol
MalwareCarbon

Carbon uses TCP and UDP for C2.

T1095
Non-Application Layer Protocol
MalwareNeo-reGeorg

Neo-reGeorg can create multiple TCP connections for a single session.

T1095
Non-Application Layer Protocol
MalwareFakeM

Some variants of FakeM use SSL to communicate with C2 servers.

T1095
Non-Application Layer Protocol
MalwareMacMa

MacMa has used a custom JSON-based protocol for its C&C communications.

T1095
Non-Application Layer Protocol
MalwareFunnyDream

FunnyDream can communicate with C2 over TCP and UDP.

T1095
Non-Application Layer Protocol
MalwareMOPSLED

MOPSLED can use a custom binary protocol over TCP for C2 communication.

T1095
Non-Application Layer Protocol
MalwareLookBack

LookBack uses a custom binary protocol over sockets for C2 communications.

T1095
Non-Application Layer Protocol
MalwareStealBit

StealBit can use the Windows Socket networking library to communicate with attacker-controlled endpoints.

T1095
Non-Application Layer Protocol
MalwarePenquin

The Penquin C2 mechanism is based on TCP and UDP packets.

T1095
Non-Application Layer Protocol
MalwareWinnti for Windows

Winnti for Windows can communicate using custom TCP.

T1095
Non-Application Layer Protocol
MalwareZIPLINE

ZIPLINE can communicate with C2 using a custom binary protocol.

T1095
Non-Application Layer Protocol
MalwaremetaMain

metaMain can establish an indirect and raw TCP socket-based connection to the C2 server.

T1095
Non-Application Layer Protocol
MalwareMis-Type

Mis-Type network traffic can communicate over a raw socket.

T1095
Non-Application Layer Protocol
MalwareStarProxy

StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.