ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S9043×

55 examples

TechniqueUsed byProcedure example
T1609
Container Administration Command
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.

T1614
System Location Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has discovered the compromised systems location through a query of the system timezone configuration and the locale settings.

T1614.001
System Language Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language.

T1649
Steal or Forge Authentication Certificates
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments.

T1677
Poisoned Pipeline Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.