ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
MalwareMivast

Mivast has the capability to download and execute .exe files.

T1105
Ingress Tool Transfer
MalwareHiddenWasp

HiddenWasp downloads a tar compressed archive from a download server to the system.

T1105
Ingress Tool Transfer
MalwareWarzoneRAT

WarzoneRAT can download and execute additional files.

T1105
Ingress Tool Transfer
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has downloaded files onto a victim machine.

T1105
Ingress Tool Transfer
MalwareXORIndex Loader

XORIndex Loader has been used to download a malicious payload to include BeaverTail.

T1105
Ingress Tool Transfer
MalwareSmall Sieve

Small Sieve has the ability to download files.

T1105
Ingress Tool Transfer
ToolRemoteUtilities

RemoteUtilities can upload and download files to and from a target machine.

T1105
Ingress Tool Transfer
Toolcertutil

certutil can be used to download files from a given URL.

T1105
Ingress Tool Transfer
ToolShimRatReporter

ShimRatReporter had the ability to download additional payloads.

T1105
Ingress Tool Transfer
ToolSliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.

T1105
Ingress Tool Transfer
ToolSILENTTRINITY

SILENTTRINITY can load additional files and tools, including Mimikatz.

T1105
Ingress Tool Transfer
ToolEmpire

Empire can upload and download to and from a victim machine.

T1105
Ingress Tool Transfer
ToolCSPY Downloader

CSPY Downloader can download additional tools to a compromised host.

T1105
Ingress Tool Transfer
ToolCARROTBALL

CARROTBALL has the ability to download and install a remote payload.

T1105
Ingress Tool Transfer
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files.

T1105
Ingress Tool Transfer
ToolAsyncRAT

AsyncRAT has the ability to download files including over SFTP.

T1105
Ingress Tool Transfer
ToolBrute Ratel C4

Brute Ratel C4 can download files to compromised hosts.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1105
Ingress Tool Transfer
ToolMCMD

MCMD can upload additional files to a compromised host.

T1105
Ingress Tool Transfer
ToolDonut

Donut can download and execute previously staged shellcode payloads.

T1105
Ingress Tool Transfer
Toolcmd

cmd can be used to copy files to/from a remotely connected external system.

T1105
Ingress Tool Transfer
Toolesentutl

esentutl can be used to copy files from a given URL.

T1105
Ingress Tool Transfer
ToolKoadic

Koadic can download additional files and tools.

T1105
Ingress Tool Transfer
ToolPupy

Pupy can upload and download to/from a victim machine.

T1105
Ingress Tool Transfer
Toolftp

ftp may be abused by adversaries to transfer tools or files from an external system into a compromised environment.

T1105
Ingress Tool Transfer
ToolQuasarRAT

QuasarRAT can download files to the victim’s machine and execute them.

T1105
Ingress Tool Transfer
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to download additional payloads to targeted systems.

T1105
Ingress Tool Transfer
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure.

T1105
Ingress Tool Transfer
MalwareCanisterWorm

CanisterWorm has downloaded and executed binaries from dead drop URLs retrieved from ICP canister C2 nodes. CanisterWorm has also downloaded kubectl to compromised environments if it was not already installed.

T1105
Ingress Tool Transfer
MalwareBADFLICK

BADFLICK has download files from its C2 server.

T1106
Native API
MalwareTrickBot

TrickBot uses the Windows API call, CreateProcessW(), to manage execution flow. TrickBot has also used Nt* API functions to perform Process Injection.

T1106
Native API
MalwareNinja

The Ninja loader can call Windows APIs for discovery, process injection, and payload decryption.

T1106
Native API
MalwarePikabot

Pikabot uses native Windows APIs to determine if the process is being debugged and analyzed, such as `CheckRemoteDebuggerPresent`, `NtQueryInformationProcess`, `ProcessDebugPort`, and `ProcessDebugFlags`. Other Pikabot variants populate a global list of Windows API addresses from the `NTDLL` and `KERNEL32` libraries, and references these items instead of calling the API items to obfuscate execution.

T1106
Native API
MalwareRCSession

RCSession can use WinSock API for communication including WSASend and WSARecv.

T1106
Native API
MalwareSynAck

SynAck parses the export tables of system DLLs to locate and call various Windows API functions.

T1106
Native API
MalwareBumblebee

Bumblebee can use multiple Native APIs.

T1106
Native API
MalwareAmadey

Amadey has used a variety of Windows API calls, including `GetComputerNameA`, `GetUserNameA`, and `CreateProcessA`.

T1106
Native API
MalwareRDFSNIFFER

RDFSNIFFER has used several Win32 API functions to interact with the victim machine.

T1106
Native API
MalwareTorisma

Torisma has used various Windows API calls.

T1106
Native API
MalwareStuxnet

Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels.

T1106
Native API
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect".

T1106
Native API
MalwareAvosLocker

AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`.

T1106
Native API
MalwarePAKLOG

PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions.

T1106
Native API
MalwareSardonic

Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running.

T1106
Native API
MalwareWindTail

WindTail can invoke Apple APIs contentsOfDirectoryAtPath, pathExtension, and (string) compare.

T1106
Native API
MalwareMisdat

Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`.

T1106
Native API
MalwareHAWKBALL

HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity.

T1106
Native API
MalwareHeartCrypt

HeartCrypt can use Windows API functions to modify the Registry and `FindResourceW`, `LoadResource`, and `LockResource` to acquire a pointer to corresponding code resources.

T1106
Native API
MalwareUrsnif

Ursnif has used CreateProcessW to create child processes.

T1106
Native API
MalwareHavoc

Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.