Real-world descriptions of how a group, tool or campaign used a technique.
56 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwareLizar | Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading. |
| T1055.001 Dynamic-link Library Injection |
ToolPowerSploit | PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process. |
| T1055.001 Dynamic-link Library Injection |
ToolIronNetInjector | IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe. |
| T1055.001 Dynamic-link Library Injection |
ToolKoadic | Koadic can perform process injection by using a reflective DLL. |
| T1055.001 Dynamic-link Library Injection |
ToolPupy | Pupy can migrate into another process using reflective DLL injection. |
| T1055.001 Dynamic-link Library Injection |
MalwareDuqu | Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.