ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareWinnti for Linux

Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity.

T1014
Rootkit
MalwareHikit

Hikit is a Rootkit that has been used by Axiom.

T1014
Rootkit
MalwareDrovorub

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

T1014
Rootkit
MalwarePoisonIvy

PoisonIvy starts a rootkit from a malicious file dropped to disk.

T1014
Rootkit
MalwareLoJax

LoJax is a UEFI BIOS rootkit deployed to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareRamsay

Ramsay has included a rootkit to evade defenses.

T1014
Rootkit
MalwareCarberp

Carberp has used user mode rootkit techniques to remain hidden on the system.

T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1014
Rootkit
MalwareHIDEDRV

HIDEDRV is a rootkit that hides certain operating system artifacts.

T1014
Rootkit
MalwareHiddenWasp

HiddenWasp uses a rootkit to hook and implement functions on the system.

T1014
Rootkit
MalwareWarzoneRAT

WarzoneRAT can include a rootkit to hide processes, files, and startup.

T1014
Rootkit
ToolHTRAN

HTRAN can install a rootkit to hide network connections from the host OS.

T1016
System Network Configuration Discovery
MalwareTrickBot

TrickBot obtains the IP address, location, and other relevant network information from the victim’s machine.

T1016
System Network Configuration Discovery
Malwarecd00r

cd00r can discover the IP for the network interface on the compromised device.

T1016
System Network Configuration Discovery
MalwarePowerDuke

PowerDuke has a command to get the victim's domain and NetBIOS name.

T1016
System Network Configuration Discovery
MalwareEKANS

EKANS can determine the domain of a compromised host.

T1016
System Network Configuration Discovery
MalwareBLINDINGCAN

BLINDINGCAN has collected the victim machine's local IP address information and MAC address.

T1016
System Network Configuration Discovery
MalwareNinja

Ninja can enumerate the IP address on compromised systems.

T1016
System Network Configuration Discovery
MalwarePikabot

Pikabot gathers victim network information through commands such as ipconfig and ipconfig /all.

T1016
System Network Configuration Discovery
MalwareAmadey

Amadey can identify the IP address of a victim machine.

T1016
System Network Configuration Discovery
MalwareProxysvc

Proxysvc collects the network adapter information and domain/username information based on current remote sessions.

T1016
System Network Configuration Discovery
MalwareOrz

Orz can gather victim proxy information.

T1016
System Network Configuration Discovery
MalwareTorisma

Torisma can collect the local MAC address using `GetAdaptersInfo` as well as the system's IP address.

T1016
System Network Configuration Discovery
MalwareNOKKI

NOKKI can gather information on the victim IP address.

T1016
System Network Configuration Discovery
Malwareyty

yty runs ipconfig /all and collects the domain name.

T1016
System Network Configuration Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about the Internet adapter configuration.

T1016
System Network Configuration Discovery
MalwareStuxnet

Stuxnet collects the IP address of a compromised system.

T1016
System Network Configuration Discovery
MalwarePOWRUNER

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1016
System Network Configuration Discovery
MalwareKOPILUWAK

KOPILUWAK can use Arp to discover a target's network configuration setttings.

T1016
System Network Configuration Discovery
MalwareSardonic

Sardonic has the ability to execute the `ipconfig` command.

T1016
System Network Configuration Discovery
MalwareEmissary

Emissary has the capability to execute the command ipconfig /all.

T1016
System Network Configuration Discovery
MalwareKEYMARBLE

KEYMARBLE gathers the MAC address of the victim’s machine.

T1016
System Network Configuration Discovery
MalwareRedLeaves

RedLeaves can obtain information about network parameters.

T1016
System Network Configuration Discovery
MalwareFelismus

Felismus collects the victim LAN IP address and sends it to the C2 server.

T1016
System Network Configuration Discovery
MalwareGeminiDuke

GeminiDuke collects information on network settings and Internet proxy settings from the victim.

T1016
System Network Configuration Discovery
MalwareHavoc

Havoc has a module for network enumeration including determining IP addresses.

T1016
System Network Configuration Discovery
MalwareGravityRAT

GravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.

T1016
System Network Configuration Discovery
MalwareInvisibleFerret

InvisibleFerret has collected the local IP address, and external IP.

T1016
System Network Configuration Discovery
MalwareStrongPity

StrongPity can identify the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwarexCaon

xCaon has used the GetAdaptersInfo() API call to get the victim's MAC address.

T1016
System Network Configuration Discovery
MalwarePLAINTEE

PLAINTEE uses the ipconfig /all command to gather the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareOceanSalt

OceanSalt can collect the victim’s IP address.

T1016
System Network Configuration Discovery
MalwareBrave Prince

Brave Prince gathers network configuration information as well as the ARP cache.

T1016
System Network Configuration Discovery
MalwareAppleSeed

AppleSeed can identify the IP of a targeted system.

T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1016
System Network Configuration Discovery
MalwareJ-magic

J-magic can compare the host and remote IPs to check if a received packet is from the infected machine.

T1016
System Network Configuration Discovery
MalwareiKitten

iKitten will look for the current IP address.

T1016
System Network Configuration Discovery
MalwareGomir

Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses.

T1016
System Network Configuration Discovery
MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1016
System Network Configuration Discovery
MalwareOlympic Destroyer

Olympic Destroyer uses API calls to enumerate the infected system's ARP table.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.