ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1204.002
Malicious File
MalwareSTARWHALE

STARWHALE has relied on victims opening a malicious Excel file for execution.

T1204.002
Malicious File
MalwareAgent Tesla

Agent Tesla has been executed through malicious e-mail attachments

T1204.002
Malicious File
MalwareAstaroth

Astaroth has used malicious files including VBS, LNK, and HTML for execution.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1204.002
Malicious File
MalwareSYSCON

SYSCON has been executed by luring victims to open malicious e-mail attachments.

T1204.002
Malicious File
MalwareHancitor

Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros.

T1204.002
Malicious File
MalwareDridex

Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.002
Malicious File
MalwareOSX/Shlayer

OSX/Shlayer has relied on users mounting and executing a malicious DMG file.

T1204.002
Malicious File
MalwareJSS Loader

JSS Loader has been executed through malicious attachments contained in spearphishing emails.

T1204.002
Malicious File
MalwareWarzoneRAT

WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution.

T1204.002
Malicious File
ToolCSPY Downloader

CSPY Downloader has been delivered via malicious documents with embedded macros.

T1204.002
Malicious File
ToolCARROTBALL

CARROTBALL has been executed through users being lured into opening malicious e-mail attachments.

T1204.002
Malicious File
ToolAsyncRAT

AsyncRAT has been executed through victims opening malicious file attachments.

T1204.002
Malicious File
ToolBrute Ratel C4

Brute Ratel C4 has gained execution through users opening malicious documents.

T1204.002
Malicious File
ToolRemcos

Remcos has been executed by luring victims into opening malicious email attachments including Excel files.

T1204.002
Malicious File
MalwareBADFLICK

BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1204.004
Malicious Copy and Paste
MalwareHavoc

The Havoc infection chain has been initiated via ClickFix lures in phishing emails.

T1204.004
Malicious Copy and Paste
MalwareKali365

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

T1205
Traffic Signaling
MalwareTONESHELL

TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values.

T1205
Traffic Signaling
MalwareBUSHWALK

BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests.

T1205
Traffic Signaling
MalwareJ-magic

J-magic can monitor TCP traffic for packets containing one of five different predefined parameters and will spawn a reverse shell if one of the parameters and the proper response string to a subsequent challenge is received.

T1205
Traffic Signaling
MalwarePUBLOAD

PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d.

T1205
Traffic Signaling
MalwareUmbreon

Umbreon provides additional access using its backdoor Espeon, providing a reverse shell upon receipt of a special packet.

T1205
Traffic Signaling
MalwareTRANSLATEXT

TRANSLATEXT has redirected clients to legitimate Gmail, Naver or Kakao pages if the clients connect with no parameters.

T1205
Traffic Signaling
MalwareREPTILE

The REPTILE reverse shell component can listen for a specialized packet in TCP, UDP, or ICMP for activation.

T1205
Traffic Signaling
MalwareChaos

Chaos provides a reverse shell is triggered upon receipt of a packet with a special string, sent to any port.

T1205
Traffic Signaling
MalwareUroburos

Uroburos can intercept the first client to server packet in the 3-way TCP handshake to determine if the packet contains the correct unique value for a specific Uroburos implant. If the value does not match, the packet and the rest of the TCP session are passed to the legitimate listening application.

T1205
Traffic Signaling
MalwareSYNful Knock

SYNful Knock can be sent instructions via special packets to change its functionality. Code for new functionality can be included in these messages.

T1205
Traffic Signaling
MalwareWinnti for Linux

Winnti for Linux has used a passive listener, capable of identifying a specific magic value before executing tasking, as a secondary command and control (C2) mechanism.

T1205
Traffic Signaling
MalwareKobalos

Kobalos is triggered by an incoming TCP connection to a legitimate service from a specific source port.

T1205
Traffic Signaling
MalwareRyuk

Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement.

T1205
Traffic Signaling
MalwarePandora

Pandora can identify if incoming HTTP traffic contains a token and if so it will intercept the traffic and process the received command.

T1205
Traffic Signaling
MalwarePenquin

Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions.

T1205
Traffic Signaling
MalwareZIPLINE

ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality.

T1205
Traffic Signaling
MalwareBRUSHFIRE

BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing.

T1205
Traffic Signaling
MalwareMini Shai-Hulud

Mini Shai-Hulud has examined commit messages for a keyword followed by base64 encoded segments to validate communications and to execute subsequent actions to include exfiltration.

T1205.001
Port Knocking
Malwarecd00r

cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication.

T1205.001
Port Knocking
MalwareMafalda

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.

T1205.001
Port Knocking
MalwareREPTILE

REPTILE has the ability to control compromised endpoints via port knocking.

T1205.001
Port Knocking
MalwaremetaMain

metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure.

T1205.002
Socket Filters
MalwareCASTLETAP

CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices.

T1205.002
Socket Filters
MalwareBPFDoor

BPFDoor uses BPF bytecode to attach a filter to a network socket to view ICMP, UDP, or TCP packets coming through ports 22 (ssh), 80 (http), and 443 (https). When BPFDoor finds a packet containing its “magic” bytes, it parses out two fields and forks itself. The parent process continues to monitor filtered traffic while the child process executes the instructions from the parsed fields.

T1205.002
Socket Filters
MalwarePenquin

Penquin installs a `TCP` and `UDP` filter on the `eth0` interface.

T1205.002
Socket Filters
MalwarePITSTOP

PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS.

T1207
Rogue Domain Controller
ToolMimikatz

Mimikatz’s LSADUMP::DCShadow module can be used to make AD updates by temporarily setting a computer to be a DC.

T1210
Exploitation of Remote Services
MalwareTrickBot

TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll.

T1210
Exploitation of Remote Services
MalwareStuxnet

Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities.

T1210
Exploitation of Remote Services
MalwareBad Rabbit

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

T1210
Exploitation of Remote Services
MalwareEmotet

Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.

T1210
Exploitation of Remote Services
MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.