ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareAstaroth

Astaroth uses WMIC to execute payloads.

T1047
Windows Management Instrumentation
MalwareQakBot

QakBot can execute WMI queries to gather information.

T1047
Windows Management Instrumentation
MalwarejRAT

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1047
Windows Management Instrumentation
MalwareINC Ransomware

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1047
Windows Management Instrumentation
MalwareFIVEHANDS

FIVEHANDS can use WMI to delete files on a target machine.

T1047
Windows Management Instrumentation
MalwareHermeticWizard

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1047
Windows Management Instrumentation
ToolCovenant

Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners.

T1047
Windows Management Instrumentation
ToolSILENTTRINITY

SILENTTRINITY can use WMI for lateral movement.

T1047
Windows Management Instrumentation
ToolPowerSploit

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1047
Windows Management Instrumentation
ToolImpacket

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1047
Windows Management Instrumentation
ToolEmpire

Empire can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
ToolPoshC2

PoshC2 has a number of modules that use WMI to execute tasks.

T1047
Windows Management Instrumentation
ToolBrute Ratel C4

Brute Ratel C4 can use WMI to move laterally.

T1047
Windows Management Instrumentation
ToolCrackMapExec

CrackMapExec can execute remote commands using Windows Management Instrumentation.

T1047
Windows Management Instrumentation
ToolKoadic

Koadic can use WMI to execute commands.

T1048
Exfiltration Over Alternative Protocol
MalwareFrameworkPOS

FrameworkPOS can use DNS tunneling for exfiltration of credit card data.

T1048
Exfiltration Over Alternative Protocol
MalwareHydraq

Hydraq connects to a predefined domain on port 443 to exfil gathered information.

T1048
Exfiltration Over Alternative Protocol
MalwareChaes

Chaes has exfiltrated its collected data from the infected machine to the C2, sometimes using the MIME protocol.

T1048
Exfiltration Over Alternative Protocol
MalwareBundlore

Bundlore uses the curl -s -L -o command to exfiltrate archived data to a URL.

T1048
Exfiltration Over Alternative Protocol
MalwareKobalos

Kobalos can exfiltrate credentials over the network via UDP.

T1048
Exfiltration Over Alternative Protocol
MalwarePoetRAT

PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account.

T1048
Exfiltration Over Alternative Protocol
ToolAADInternals

AADInternals can directly download cloud user data such as OneDrive files.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareIcedID

IcedID has exfiltrated collected data via HTTPS.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareBRUSHFIRE

BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
ToolRclone

Rclone can exfiltrate data over SFTP or HTTPS via WebDAV.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWindTail

WindTail has the ability to automatically exfiltrate files using the macOS built-in utility /usr/bin/curl.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareInvisibleFerret

InvisibleFerret has used FTP to exfiltrate files and directories using the command `ssh_upload` which contains with six subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr` and `sfind` that had varying functions. InvisibleFerret has exfiltrated stolen files and data to the C2 servers over ports 1224, 2245 and 8637.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareBrave Prince

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCosmicDuke

CosmicDuke exfiltrates collected files over FTP or WebDAV. Exfiltration servers can be separately configured from C2 servers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePUBLOAD

PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareSocGholish

SocGholish can exfiltrate data directly to its C2 domain via HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareRemsec

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCharmPower

CharmPower can send victim data via FTP with credentials hardcoded in the script.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKONNI

KONNI has used FTP to exfiltrate reconnaissance data out.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCORALDECK

CORALDECK has exfiltrated data in HTTP POST headers.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Malwareccf32

ccf32 can upload collected data and files to an FTP server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWARPWIRE

WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCherry Picker

Cherry Picker exfiltrates files over FTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCarbon

Carbon uses HTTP to send data to the C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareKessel

Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwarePoetRAT

PoetRAT has used ftp for exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareAgent Tesla

Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCookieMiner

CookieMiner has used the curl --upload-file command to exfiltrate data over HTTP.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareDok

Dok exfiltrates logs of its execution stored in the /tmp folder over FTP using the curl command.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
ToolRclone

Rclone can exfiltrate data over FTP or HTTP, including HTTP via WebDAV.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload files from a compromised host.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Toolftp

ftp may be used to exfiltrate data separate from the main command and control protocol.

T1049
System Network Connections Discovery
MalwareTorisma

Torisma can use `WTSEnumerateSessionsW` to monitor remote desktop connections.

T1049
System Network Connections Discovery
MalwarePOWRUNER

POWRUNER may collect active network connections by running netstat -an on a victim.

T1049
System Network Connections Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.