ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1029
Scheduled Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure.

T1029
Scheduled Transfer
MalwareShadowPad

ShadowPad has sent data back to C2 every 8 hours.

T1029
Scheduled Transfer
MalwarejRAT

jRAT can be configured to reconnect at certain intervals.

T1029
Scheduled Transfer
MalwareADVSTORESHELL

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

T1030
Data Transfer Size Limits
MalwareAppleSeed

AppleSeed has divided files if the size is 0x1000000 bytes or more.

T1030
Data Transfer Size Limits
MalwareRDAT

RDAT can upload a file via HTTP POST response to the C2 split into 102,400-byte portions. RDAT can also download data from the C2 which is split into 81,920-byte portions.

T1030
Data Transfer Size Limits
MalwareObliqueRAT

ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration.

T1030
Data Transfer Size Limits
MalwarePOSHSPY

POSHSPY uploads data in 2048-byte chunks.

T1030
Data Transfer Size Limits
MalwareCarbanak

Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes .

T1030
Data Transfer Size Limits
MalwareOopsIE

OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.

T1030
Data Transfer Size Limits
MalwareCobalt Strike

Cobalt Strike will break large data sets into smaller chunks for exfiltration.

T1030
Data Transfer Size Limits
MalwareKessel

Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries.

T1030
Data Transfer Size Limits
MalwareStealBit

StealBit can be configured to exfiltrate files at a specified rate to evade network detection mechanisms.

T1030
Data Transfer Size Limits
MalwareLunarWeb

LunarWeb can split exfiltrated data that exceeds 1.33 MB in size into multiple random sized parts between 384 and 512 KB.

T1030
Data Transfer Size Limits
MalwareKevin

Kevin can exfiltrate data to the C2 server in 27-character chunks.

T1030
Data Transfer Size Limits
MalwareHelminth

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

T1030
Data Transfer Size Limits
ToolRclone

The Rclone "chunker" overlay supports splitting large files in smaller chunks during upload to circumvent size limits.

T1030
Data Transfer Size Limits
ToolMythic

Mythic supports custom chunk sizes used to upload/download files.

T1033
System Owner/User Discovery
MalwareTrickBot

TrickBot can identify the user and groups the user belongs to on a compromised host.

T1033
System Owner/User Discovery
MalwarePowerDuke

PowerDuke has commands to get the current user's name and SID.

T1033
System Owner/User Discovery
MalwareRCSession

RCSession can gather system owner information, including user and administrator privileges.

T1033
System Owner/User Discovery
MalwareSpark

Spark has run the whoami command and has a built-in command to identify the user logged in.

T1033
System Owner/User Discovery
MalwareSynAck

SynAck gathers user names from infected hosts.

T1033
System Owner/User Discovery
MalwareBumblebee

Bumblebee has the ability to identify the user name.

T1033
System Owner/User Discovery
MalwareAmadey

Amadey has collected the user name from a compromised host using `GetUserNameA`.

T1033
System Owner/User Discovery
MalwareNOKKI

NOKKI can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
Malwareyty

yty collects the victim’s username.

T1033
System Owner/User Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects the current username from the victim.

T1033
System Owner/User Discovery
MalwareIronWind

IronWind can enumerate the username on victim's systems.

T1033
System Owner/User Discovery
MalwareGet2

Get2 has the ability to identify the current username of an infected host.

T1033
System Owner/User Discovery
MalwarePOWRUNER

POWRUNER may collect information about the currently logged in user by running whoami on a victim.

T1033
System Owner/User Discovery
MalwareKOPILUWAK

KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details.

T1033
System Owner/User Discovery
MalwareLinux Rabbit

Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain.

T1033
System Owner/User Discovery
MalwareExaramel for Linux

Exaramel for Linux can run whoami to identify the system owner.

T1033
System Owner/User Discovery
MalwareHAWKBALL

HAWKBALL can collect the user name of the system.

T1033
System Owner/User Discovery
MalwareRedLeaves

RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions.

T1033
System Owner/User Discovery
MalwareFelismus

Felismus collects the current username and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareHavoc

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1033
System Owner/User Discovery
MalwareGravityRAT

GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status).

T1033
System Owner/User Discovery
MalwareInvisibleFerret

InvisibleFerret has identified the user’s UUID and username through the "pay" module.

T1033
System Owner/User Discovery
MalwareHAPPYWORK

can collect the victim user name.

T1033
System Owner/User Discovery
MalwareWinMM

WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system.

T1033
System Owner/User Discovery
MalwareTONESHELL

TONESHELL has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwarePyDCrypt

PyDCrypt has probed victim machines with whoami and has collected the username from the machine.

T1033
System Owner/User Discovery
MalwareBOOKWORM

BOOKWORM has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwareSslMM

SslMM sends the logged-on username to its hard-coded C2.

T1033
System Owner/User Discovery
MalwareAria-body

Aria-body has the ability to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareEmotet

Emotet has enumerated all users connected to network shares.

T1033
System Owner/User Discovery
MalwareCrimson

Crimson can identify the user on a targeted system.

T1033
System Owner/User Discovery
MalwareTurian

Turian can retrieve usernames.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.