ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareQakBot

QakBot can identify remote systems through the net view command.

T1018
Remote System Discovery
MalwareComnie

Comnie runs the net view command

T1018
Remote System Discovery
MalwareOSInfo

OSInfo performs a connection test to discover remote systems in the network

T1018
Remote System Discovery
MalwareBitPaymer

BitPaymer can use net view to discover remote systems.

T1018
Remote System Discovery
MalwareHermeticWizard

HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.`

T1018
Remote System Discovery
ToolNet

Commands such as net view can be used in Net to gather information about available remote systems.

T1018
Remote System Discovery
ToolBloodHound

BloodHound can enumerate and collect the properties of domain computers, including domain controllers.

T1018
Remote System Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate and collect the properties of domain computers.

T1018
Remote System Discovery
ToolArp

Arp can be used to display a host's ARP cache, which may include address resolutions for remote systems.

T1018
Remote System Discovery
ToolROADTools

ROADTools can enumerate Azure AD systems and devices.

T1018
Remote System Discovery
ToolNltest

Nltest may be used to enumerate remote domain controllers using options such as /dclist and /dsgetdc.

T1018
Remote System Discovery
ToolNBTscan

NBTscan can list NetBIOS computer names.

T1018
Remote System Discovery
ToolPing

Ping can be used to identify remote systems within a network.

T1018
Remote System Discovery
ToolCrackMapExec

CrackMapExec can discover active IP addresses, along with the machine name, within a targeted network.

T1018
Remote System Discovery
ToolAdFind

AdFind has the ability to query Active Directory for computers.

T1018
Remote System Discovery
MalwareCanisterWorm

CanisterWorm has scanned the local /24 subnet for new targets.

T1020
Automated Exfiltration
MalwareStrongPity

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1020
Automated Exfiltration
MalwareHannotog

Hannotog can upload encyrpted data for exfiltration.

T1020
Automated Exfiltration
MalwareCosmicDuke

CosmicDuke exfiltrates collected files automatically over FTP to remote servers.

T1020
Automated Exfiltration
MalwareMachete

Machete’s collected files are exfiltrated automatically to remote servers.

T1020
Automated Exfiltration
MalwareDoki

Doki has used a script that gathers information from a hardcoded list of IP addresses and uploads to an Ngrok URL.

T1020
Automated Exfiltration
MalwareRover

Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe.

T1020
Automated Exfiltration
MalwareLightNeuron

LightNeuron can be configured to automatically exfiltrate files under a specified directory.

T1020
Automated Exfiltration
MalwarePeppy

Peppy has the ability to automatically exfiltrate files and keylogs.

T1020
Automated Exfiltration
MalwareTINYTYPHON

When a document is found matching one of the extensions in the configuration, TINYTYPHON uploads it to the C2 server.

T1020
Automated Exfiltration
MalwareAttor

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

T1020
Automated Exfiltration
MalwareCrutch

Crutch has automatically exfiltrated stolen files to Dropbox.

T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1020
Automated Exfiltration
MalwareUSBStealer

USBStealer automatically exfiltrates collected files via removable media when an infected device connects to an air-gapped victim machine after initially being connected to an internet-enabled victim machine.

T1020
Automated Exfiltration
MalwareTajMahal

TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2.

T1020
Automated Exfiltration
MalwareRaccoon Stealer

Raccoon Stealer will automatically collect and exfiltrate data identified in received configuration files from command and control nodes.

T1020
Automated Exfiltration
MalwareSolar

Solar can automatically exfitrate files from compromised systems.

T1020
Automated Exfiltration
MalwareOutSteel

OutSteel can automatically upload collected files to its C2 server.

T1020
Automated Exfiltration
MalwareEbury

If credentials are not collected for two weeks, Ebury encrypts the credentials using a public key and sends them via UDP to an IP address located in the DNS TXT record.

T1020
Automated Exfiltration
ToolShimRatReporter

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1020
Automated Exfiltration
ToolEmpire

Empire has the ability to automatically send collected data back to the threat actors' C2.

T1020
Automated Exfiltration
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there.

T1021
Remote Services
MalwareStuxnet

Stuxnet can propagate via peer-to-peer communication and updates using RPC.

T1021
Remote Services
MalwareKivars

Kivars has the ability to remotely trigger keyboard input and mouse clicks.

T1021
Remote Services
MalwareMacMa

MacMa can manage remote screen sessions.

T1021
Remote Services
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use RPC for lateral movement.

T1021.001
Remote Desktop Protocol
MalwarereGeorg

reGeorg can be used to tunnel RDP connections.

T1021.001
Remote Desktop Protocol
MalwareDarkComet

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

T1021.001
Remote Desktop Protocol
MalwarezwShell

zwShell has used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
MalwareCarbanak

Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions.

T1021.001
Remote Desktop Protocol
MalwareSDBbot

SDBbot has the ability to use RDP to connect to victim's machines.

T1021.001
Remote Desktop Protocol
MalwarePysa

Pysa has laterally moved using RDP connections.

T1021.001
Remote Desktop Protocol
MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1021.001
Remote Desktop Protocol
MalwareServHelper

ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel.

T1021.001
Remote Desktop Protocol
MalwareRevenge RAT

Revenge RAT has a plugin to perform RDP access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.