ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0692×

53 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
ToolSILENTTRINITY

SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions.

T1689
Downgrade Attack
ToolSILENTTRINITY

SILENTTRINITY can downgrade NTLM to capture NTLM hashes.

T1690
Prevent Command History Logging
ToolSILENTTRINITY

SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.