Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareXORIndex Loader | XORIndex Loader has used HTTPS POST to communicate with C2. |
| T1071.001 Web Protocols |
MalwareSmall Sieve | Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS. |
| T1071.001 Web Protocols |
ToolCovenant | Covenant can establish command and control via HTTP. |
| T1071.001 Web Protocols |
ToolShimRatReporter | ShimRatReporter communicated over HTTP with preconfigured C2 servers. |
| T1071.001 Web Protocols |
ToolSliver | Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.001 Web Protocols |
Toolevilginx2 | evilginx2 can proxy HTTPS connections between victims and destination websites. |
| T1071.001 Web Protocols |
ToolEmpire | Empire can conduct command and control over protocols like HTTP and HTTPS. |
| T1071.001 Web Protocols |
ToolFRP | FRP has the ability to use HTTP and HTTPS to enable the forwarding of requests for internal services via domain name. |
| T1071.001 Web Protocols |
ToolPcShare | PcShare has used HTTP for C2 communication. |
| T1071.001 Web Protocols |
ToolPoshC2 | PoshC2 can use protocols like HTTP/HTTPS for command and control traffic. |
| T1071.001 Web Protocols |
ToolCSPY Downloader | CSPY Downloader can use GET requests to download additional payloads from C2. |
| T1071.001 Web Protocols |
ToolBrute Ratel C4 | Brute Ratel C4 can use HTTPS and HTTPS for C2 communication. |
| T1071.001 Web Protocols |
ToolOut1 | Out1 can use HTTP and HTTPS in communications with remote hosts. |
| T1071.001 Web Protocols |
ToolMCMD | MCMD can use HTTPS in communication with C2 web servers. |
| T1071.001 Web Protocols |
ToolDonut | Donut can use HTTP to download previously staged shellcode payloads. |
| T1071.001 Web Protocols |
ToolKoadic | Koadic has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
ToolPupy | Pupy can communicate over HTTP for C2. |
| T1071.001 Web Protocols |
ToolMythic | Mythic supports HTTP-based C2 profiles. |
| T1071.001 Web Protocols |
ToolQuick Assist | Quick Assist communicates over TCP 443 via HTTPS to a remote session server, under which RDP traffic is transferred. |
| T1071.001 Web Protocols |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains. |
| T1071.001 Web Protocols |
MalwareMini Shai-Hulud | Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains. |
| T1071.001 Web Protocols |
MalwareKali365 | Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture. |
| T1071.002 File Transfer Protocols |
MalwareNOKKI | NOKKI has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareHavoc | Havoc can use an SMB listener for C2 communication. |
| T1071.002 File Transfer Protocols |
MalwareSharpDisco | SharpDisco has the ability to transfer data between SMB shares. |
| T1071.002 File Transfer Protocols |
MalwareBADHATCH | BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwarePUBLOAD | PUBLOAD has used `curl` for data exfiltration over FTP. |
| T1071.002 File Transfer Protocols |
MalwareRegin | The Regin malware platform supports many standard protocols, including SMB. |
| T1071.002 File Transfer Protocols |
MalwareKazuar | Kazuar uses FTP and FTPS to communicate with the C2 server. |
| T1071.002 File Transfer Protocols |
MalwareXAgentOSX | XAgentOSX contains the ftpUpload function to use the FTPManager:uploadFile method to upload files from the target system. |
| T1071.002 File Transfer Protocols |
MalwareAttor | Attor has used FTP protocol for C2 communication. |
| T1071.002 File Transfer Protocols |
MalwareCobalt Strike | Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports. |
| T1071.002 File Transfer Protocols |
MalwarePoetRAT | PoetRAT has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareZxShell | ZxShell has used FTP for C2 connections. |
| T1071.002 File Transfer Protocols |
MalwareJPIN | JPIN can communicate over FTP. |
| T1071.002 File Transfer Protocols |
MalwareDisco | Disco can use SMB to transfer files. |
| T1071.002 File Transfer Protocols |
MalwareQilin | Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system. |
| T1071.002 File Transfer Protocols |
MalwareShadowPad | ShadowPad has used FTP for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwareSYSCON | SYSCON has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolCARROTBALL | CARROTBALL has the ability to use FTP in C2 communications. |
| T1071.002 File Transfer Protocols |
ToolMythic | Mythic supports SMB-based peer-to-peer C2 profiles. |
| T1071.003 Mail Protocols |
MalwarePowerExchange | PowerExchange can receive and send back the results of executed C2 commands through email. |
| T1071.003 Mail Protocols |
MalwareOLDBAIT | OLDBAIT can use SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareIMAPLoader | IMAPLoader uses the IMAP email protocol for command and control purposes. |
| T1071.003 Mail Protocols |
MalwareRDAT | RDAT can use email attachments for C2 communications. |
| T1071.003 Mail Protocols |
MalwareNavRAT | NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP. |
| T1071.003 Mail Protocols |
MalwareCORESHELL | CORESHELL can communicate over SMTP and POP3 for C2. |
| T1071.003 Mail Protocols |
MalwareRemsec | Remsec is capable of using SMTP for C2. |
| T1071.003 Mail Protocols |
MalwareLightNeuron | LightNeuron uses SMTP for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.