ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0154×

73 examples

TechniqueUsed byProcedure example
T1134.003
Make and Impersonate Token
MalwareCobalt Strike

Cobalt Strike can make tokens from known credentials.

T1134.004
Parent PID Spoofing
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

T1135
Network Share Discovery
MalwareCobalt Strike

Cobalt Strike can query shared drives on the local system.

T1137.001
Office Template Macros
MalwareCobalt Strike

Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission.

T1140
Deobfuscate/Decode Files or Information
MalwareCobalt Strike

Cobalt Strike can deobfuscate shellcode using a rolling XOR and decrypt metadata from Beacon sessions. The Cobalt Strike loader component can also decrypt the .bss section of the Beacon binary prior to execution.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1197
BITS Jobs
MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

T1203
Exploitation for Client Execution
MalwareCobalt Strike

Cobalt Strike can exploit Oracle Java vulnerabilities for execution, including CVE-2011-3544, CVE-2013-2465, CVE-2012-4681, and CVE-2013-2460.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1497.002
User Activity Based Checks
MalwareCobalt Strike

The Cobalt Strike loader can use the `MessageBoxA` API to prompt for user interaction as an anti-sandbox measure.

T1518
Software Discovery
MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

T1543.003
Windows Service
MalwareCobalt Strike

Cobalt Strike can install a new service.

T1548.002
Bypass User Account Control
MalwareCobalt Strike

Cobalt Strike can use a number of known techniques to bypass Windows UAC.

T1548.003
Sudo and Sudo Caching
MalwareCobalt Strike

Cobalt Strike can use sudo to run a command.

T1550.002
Pass the Hash
MalwareCobalt Strike

Cobalt Strike can perform pass the hash.

T1553.002
Code Signing
MalwareCobalt Strike

Cobalt Strike can use self signed Java applets to execute signed applet attacks.

T1564.010
Process Argument Spoofing
MalwareCobalt Strike

Cobalt Strike can use spoof arguments in spawned processes that execute beacon commands.

T1569.002
Service Execution
MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

T1572
Protocol Tunneling
MalwareCobalt Strike

Cobalt Strike uses a custom command and control protocol that is encapsulated in HTTP, HTTPS, or DNS. In addition, it conducts peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1573.001
Symmetric Cryptography
MalwareCobalt Strike

Cobalt Strike has the ability to use AES-256 symmetric encryption in CBC mode with HMAC-SHA-256 to encrypt task commands and XOR to encrypt shell code and configuration data.

T1573.002
Asymmetric Cryptography
MalwareCobalt Strike

Cobalt Strike can use RSA asymmetric encryption with PKCS1 padding to encrypt data sent to the C2 server.

T1620
Reflective Code Loading
MalwareCobalt Strike

Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process by loading the CLR.

T1685
Disable or Modify Tools
MalwareCobalt Strike

Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.