Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134.003 Make and Impersonate Token |
MalwareCobalt Strike | Cobalt Strike can make tokens from known credentials. |
| T1134.004 Parent PID Spoofing |
MalwareCobalt Strike | Cobalt Strike can spawn processes with alternate PPIDs. |
| T1135 Network Share Discovery |
MalwareCobalt Strike | Cobalt Strike can query shared drives on the local system. |
| T1137.001 Office Template Macros |
MalwareCobalt Strike | Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCobalt Strike | Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1197 BITS Jobs |
MalwareCobalt Strike | Cobalt Strike can download a hosted "beacon" payload using BITSAdmin. |
| T1203 Exploitation for Client Execution |
MalwareCobalt Strike | Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460. |
| T1218.011 Rundll32 |
MalwareCobalt Strike | Cobalt Strike can use `rundll32.exe` to load DLL from the command line. |
| T1497.002 User Activity Based Checks |
MalwareCobalt Strike | The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure. |
| T1518 Software Discovery |
MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| T1543.003 Windows Service |
MalwareCobalt Strike | Cobalt Strike can install a new service. |
| T1548.002 Bypass User Account Control |
MalwareCobalt Strike | Cobalt Strike can use a number of known techniques to bypass Windows UAC. |
| T1548.003 Sudo and Sudo Caching |
MalwareCobalt Strike | Cobalt Strike can use |
| T1550.002 Pass the Hash |
MalwareCobalt Strike | Cobalt Strike can perform pass the hash. |
| T1553.002 Code Signing |
MalwareCobalt Strike | Cobalt Strike can use self signed Java applets to execute signed applet attacks. |
| T1564.010 Process Argument Spoofing |
MalwareCobalt Strike | Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| T1572 Protocol Tunneling |
MalwareCobalt Strike | Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1573.001 Symmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data. |
| T1573.002 Asymmetric Cryptography |
MalwareCobalt Strike | Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server. |
| T1620 Reflective Code Loading |
MalwareCobalt Strike | Cobalt Strike's |
| T1685 Disable or Modify Tools |
MalwareCobalt Strike | Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.