ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareXORIndex Loader

XORIndex Loader has used HTTPS POST to communicate with C2.

T1071.001
Web Protocols
MalwareSmall Sieve

Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS.

T1071.001
Web Protocols
ToolCovenant

Covenant can establish command and control via HTTP.

T1071.001
Web Protocols
ToolShimRatReporter

ShimRatReporter communicated over HTTP with preconfigured C2 servers.

T1071.001
Web Protocols
ToolSliver

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.001
Web Protocols
Toolevilginx2

evilginx2 can proxy HTTPS connections between victims and destination websites.

T1071.001
Web Protocols
ToolEmpire

Empire can conduct command and control over protocols like HTTP and HTTPS.

T1071.001
Web Protocols
ToolFRP

FRP has the ability to use HTTP and HTTPS to enable the forwarding of requests for internal services via domain name.

T1071.001
Web Protocols
ToolPcShare

PcShare has used HTTP for C2 communication.

T1071.001
Web Protocols
ToolPoshC2

PoshC2 can use protocols like HTTP/HTTPS for command and control traffic.

T1071.001
Web Protocols
ToolCSPY Downloader

CSPY Downloader can use GET requests to download additional payloads from C2.

T1071.001
Web Protocols
ToolBrute Ratel C4

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.

T1071.001
Web Protocols
ToolOut1

Out1 can use HTTP and HTTPS in communications with remote hosts.

T1071.001
Web Protocols
ToolMCMD

MCMD can use HTTPS in communication with C2 web servers.

T1071.001
Web Protocols
ToolDonut

Donut can use HTTP to download previously staged shellcode payloads.

T1071.001
Web Protocols
ToolKoadic

Koadic has used HTTP for C2 communications.

T1071.001
Web Protocols
ToolPupy

Pupy can communicate over HTTP for C2.

T1071.001
Web Protocols
ToolMythic

Mythic supports HTTP-based C2 profiles.

T1071.001
Web Protocols
ToolQuick Assist

Quick Assist communicates over TCP 443 via HTTPS to a remote session server, under which RDP traffic is transferred.

T1071.001
Web Protocols
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains.

T1071.001
Web Protocols
MalwareMini Shai-Hulud

Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains.

T1071.001
Web Protocols
MalwareKali365

Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture.

T1071.002
File Transfer Protocols
MalwareNOKKI

NOKKI has used FTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareHavoc

Havoc can use an SMB listener for C2 communication.

T1071.002
File Transfer Protocols
MalwareSharpDisco

SharpDisco has the ability to transfer data between SMB shares.

T1071.002
File Transfer Protocols
MalwareBADHATCH

BADHATCH can emulate an FTP server to connect to actor-controlled C2 servers.

T1071.002
File Transfer Protocols
MalwareMachete

Machete uses FTP for Command & Control.

T1071.002
File Transfer Protocols
MalwarePUBLOAD

PUBLOAD has used `curl` for data exfiltration over FTP.

T1071.002
File Transfer Protocols
MalwareRegin

The Regin malware platform supports many standard protocols, including SMB.

T1071.002
File Transfer Protocols
MalwareKazuar

Kazuar uses FTP and FTPS to communicate with the C2 server.

T1071.002
File Transfer Protocols
MalwareXAgentOSX

XAgentOSX contains the ftpUpload function to use the FTPManager:uploadFile method to upload files from the target system.

T1071.002
File Transfer Protocols
MalwareAttor

Attor has used FTP protocol for C2 communication.

T1071.002
File Transfer Protocols
MalwareCobalt Strike

Cobalt Strike can conduct peer-to-peer communication over Windows named pipes encapsulated in the SMB protocol. All protocols use their standard assigned ports.

T1071.002
File Transfer Protocols
MalwarePoetRAT

PoetRAT has used FTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareZxShell

ZxShell has used FTP for C2 connections.

T1071.002
File Transfer Protocols
MalwareJPIN

JPIN can communicate over FTP.

T1071.002
File Transfer Protocols
MalwareDisco

Disco can use SMB to transfer files.

T1071.002
File Transfer Protocols
MalwareQilin

Qilin can use WinSCP for the secure file transfer of the Linux ransomware binary to a targeted system.

T1071.002
File Transfer Protocols
MalwareShadowPad

ShadowPad has used FTP for C2 communications.

T1071.002
File Transfer Protocols
MalwareSYSCON

SYSCON has the ability to use FTP in C2 communications.

T1071.002
File Transfer Protocols
ToolCARROTBALL

CARROTBALL has the ability to use FTP in C2 communications.

T1071.002
File Transfer Protocols
ToolMythic

Mythic supports SMB-based peer-to-peer C2 profiles.

T1071.003
Mail Protocols
MalwarePowerExchange

PowerExchange can receive and send back the results of executed C2 commands through email.

T1071.003
Mail Protocols
MalwareOLDBAIT

OLDBAIT can use SMTP for C2.

T1071.003
Mail Protocols
MalwareIMAPLoader

IMAPLoader uses the IMAP email protocol for command and control purposes.

T1071.003
Mail Protocols
MalwareRDAT

RDAT can use email attachments for C2 communications.

T1071.003
Mail Protocols
MalwareNavRAT

NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP.

T1071.003
Mail Protocols
MalwareCORESHELL

CORESHELL can communicate over SMTP and POP3 for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.003
Mail Protocols
MalwareLightNeuron

LightNeuron uses SMTP for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.