ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055.001×

56 examples

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareLizar

Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading.

T1055.001
Dynamic-link Library Injection
ToolPowerSploit

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1055.001
Dynamic-link Library Injection
ToolIronNetInjector

IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe.

T1055.001
Dynamic-link Library Injection
ToolKoadic

Koadic can perform process injection by using a reflective DLL.

T1055.001
Dynamic-link Library Injection
ToolPupy

Pupy can migrate into another process using reflective DLL injection.

T1055.001
Dynamic-link Library Injection
MalwareDuqu

Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.