ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareCreepySnail

CreepySnail can connect to C2 for data exfiltration.

T1041
Exfiltration Over C2 Channel
MalwareTroll Stealer

Troll Stealer exfiltrates collected information to its command and control infrastructure.

T1041
Exfiltration Over C2 Channel
MalwareEbury

Ebury exfiltrates a list of outbound and inbound SSH sessions using OpenSSH's `known_host` files and `wtmp` records. Ebury can exfiltrate SSH credentials through custom DNS queries or use the command `Xcat` to send the process's ssh session's credentials to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwarenjRAT

njRAT has used C2 infrastructure to receive stolen information from the infected machine including screenshots and other system information.

T1041
Exfiltration Over C2 Channel
MalwareManjusaka

Manjusaka data exfiltration takes place over HTTP channels.

T1041
Exfiltration Over C2 Channel
MalwareIceApple

IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2.

T1041
Exfiltration Over C2 Channel
MalwareShai-Hulud

Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL.

T1041
Exfiltration Over C2 Channel
MalwaremetaMain

metaMain can upload collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSideTwist

SideTwist has exfiltrated data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareMechaFlounder

MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2.

T1041
Exfiltration Over C2 Channel
MalwarePsylo

Psylo exfiltrates data to its C2 server over the same protocol as C2 communications.

T1041
Exfiltration Over C2 Channel
MalwareMis-Type

Mis-Type has transmitted collected files and data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareXCSSET

XCSSET retrieves files that match the pattern defined in the INAME_QUERY variable within the user's home directory, such as `*test.txt`, and are below a specific size limit. It then archives the files and exfiltrates the data over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareOctopus

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAppleJeus

AppleJeus has exfiltrated collected host information to a C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSTARWHALE

STARWHALE can exfiltrate collected data to its C2 servers.

T1041
Exfiltration Over C2 Channel
MalwareIndustroyer

Industroyer sends information about hardware profiles and previously-received commands back to the C2 server in a POST-request.

T1041
Exfiltration Over C2 Channel
MalwareKevin

Kevin can send data from the victim host through a DNS C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareGoopy

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareRemexi

Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel.

T1041
Exfiltration Over C2 Channel
MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

T1041
Exfiltration Over C2 Channel
MalwareQakBot

QakBot can send stolen information to C2 nodes including passwords, accounts, and emails.

T1041
Exfiltration Over C2 Channel
MalwareBACKSPACE

Adversaries can direct BACKSPACE to upload files to the C2 Server.

T1041
Exfiltration Over C2 Channel
MalwareADVSTORESHELL

ADVSTORESHELL exfiltrates data over the same channel used for C2.

T1041
Exfiltration Over C2 Channel
MalwareStrifeWater

StrifeWater can send data and files from a compromised host to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareWarzoneRAT

WarzoneRAT can send collected victim data to its C2 server.

T1041
Exfiltration Over C2 Channel
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests.

T1041
Exfiltration Over C2 Channel
MalwareXORIndex Loader

XORIndex Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
ToolShimRatReporter

ShimRatReporter sent generated reports to the C2 via HTTP POST requests.

T1041
Exfiltration Over C2 Channel
ToolSliver

Sliver can exfiltrate files from the victim using the download command.

T1041
Exfiltration Over C2 Channel
ToolSILENTTRINITY

SILENTTRINITY can transfer files from an infected host to the C2 server.

T1041
Exfiltration Over C2 Channel
ToolEmpire

Empire can send data gathered from a target through the command and control channel.

T1041
Exfiltration Over C2 Channel
ToolPcShare

PcShare can upload files and information from a compromised host to its C2 servers.

T1041
Exfiltration Over C2 Channel
ToolImminent Monitor

Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2.

T1041
Exfiltration Over C2 Channel
ToolPupy

Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server.

T1041
Exfiltration Over C2 Channel
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org.

T1041
Exfiltration Over C2 Channel
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains.

T1046
Network Service Discovery
MalwareHDoor

HDoor scans to identify open ports on the victim.

T1046
Network Service Discovery
MalwareMURKYTOP

MURKYTOP has the capability to scan for open ports on hosts in a connected network.

T1046
Network Service Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea can use a network scanning module to identify ICS-related ports.

T1046
Network Service Discovery
MalwareBADHATCH

BADHATCH can check for open ports on a computer by establishing a TCP connection.

T1046
Network Service Discovery
MalwareHildegard

Hildegard has used masscan to look for kubelets in the internal Kubernetes network.

T1046
Network Service Discovery
MalwareInvisiMole

InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols.

T1046
Network Service Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can scan networks for open ports and listening services.

T1046
Network Service Discovery
MalwareLucifer

Lucifer can scan for open ports including TCP ports 135 and 1433.

T1046
Network Service Discovery
MalwareBlackEnergy

BlackEnergy has conducted port scans on a host.

T1046
Network Service Discovery
MalwareConficker

Conficker scans for other machines to infect.

T1046
Network Service Discovery
MalwareChina Chopper

China Chopper's server component can spider authentication portals.

T1046
Network Service Discovery
MalwareLightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist file`.It also utilizes Apple's CWWiFiClient API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.

T1046
Network Service Discovery
MalwareRemsec

Remsec has a plugin that can perform ARP scanning as well as port scanning.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.