ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1071.004
DNS
MalwareHelminth

Helminth can use DNS for C2.

T1071.004
DNS
MalwareDenis

Denis has used DNS tunneling for C2 communications.

T1071.004
DNS
ToolSliver

Sliver can support C2 communications over DNS.

T1071.004
DNS
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1071.004
DNS
ToolMythic

Mythic supports DNS-based C2 profiles.

T1071.005
Publish/Subscribe Protocols
MalwareGLOOXMAIL

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2.

T1072
Software Deployment Tools
MalwareWiper

It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware.

T1074
Data Staged
MalwareQUIETCANARY

QUIETCANARY has the ability to stage data prior to exfiltration.

T1074
Data Staged
MalwareShark

Shark has stored information in folders named `U1` and `U2` prior to exfiltration.

T1074
Data Staged
MalwareKobalos

Kobalos can write captured SSH connection credentials to a file under the /var/run directory with a .pid extension for exfiltration.

T1074
Data Staged
MalwareKevin

Kevin can create directories to store logs and other collected data.

T1074.001
Local Data Staging
MalwareExaramel for Windows

Exaramel for Windows specifies a path to store files scheduled for exfiltration.

T1074.001
Local Data Staging
MalwareNOKKI

NOKKI can collect data from the victim and stage it in LOCALAPPDATA%\MicroSoft Updatea\uplog.tmp.

T1074.001
Local Data Staging
MalwareKOPILUWAK

KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine.

T1074.001
Local Data Staging
MalwareVersaMem

VersaMem staged captured credentials locally at `/tmp/.temp.data`.

T1074.001
Local Data Staging
MalwarePAKLOG

PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`.

T1074.001
Local Data Staging
MalwareUrsnif

Ursnif has used tmp files to stage gathered information.

T1074.001
Local Data Staging
MalwareFrameworkPOS

FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\.

T1074.001
Local Data Staging
MalwareInvisibleFerret

InvisibleFerret has staged data in consolidated folders prior to exfiltration.

T1074.001
Local Data Staging
MalwareRainyDay

RainyDay can use a file exfiltration tool to copy files to C:\ProgramData\Adobe\temp prior to exfiltration.

T1074.001
Local Data Staging
MalwareAppleSeed

AppleSeed can stage files in a central location prior to exfiltration.

T1074.001
Local Data Staging
MalwareNETWIRE

NETWIRE has the ability to write collected data to a file created in the ./LOGS directory.

T1074.001
Local Data Staging
MalwareMirrorStealer

MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`.

T1074.001
Local Data Staging
MalwareTurian

Turian can store copied files in a specific directory prior to exfiltration.

T1074.001
Local Data Staging
MalwareMachete

Machete stores files and logs in a folder on the local drive.

T1074.001
Local Data Staging
MalwarePowerLess

PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`.

T1074.001
Local Data Staging
MalwarePrikormka

Prikormka creates a directory, %USERPROFILE%\AppData\Local\SKC\, which is used to store collected log files.

T1074.001
Local Data Staging
MalwareMafalda

Mafalda can place retrieved files into a destination directory.

T1074.001
Local Data Staging
MalwareAuTo Stealer

AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration.

T1074.001
Local Data Staging
MalwareSombRAT

SombRAT can store harvested data in a custom database under the %TEMP% directory.

T1074.001
Local Data Staging
MalwareFLASHFLOOD

FLASHFLOOD stages data it copies from the local system or removable drives in the "%WINDIR%\$NtUninstallKB885884$\" directory.

T1074.001
Local Data Staging
MalwareLoFiSe

LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders.

T1074.001
Local Data Staging
MalwareCuckoo Stealer

Cuckoo Stealer has staged collected application data from Safari, Notes, and Keychain to `/var/folder`.

T1074.001
Local Data Staging
MalwareInvisiMole

InvisiMole determines a working directory where it stores all the gathered data about the compromised machine.

T1074.001
Local Data Staging
MalwareMarkiRAT

MarkiRAT can store collected data locally in a created .nfo file.

T1074.001
Local Data Staging
MalwareKazuar

Kazuar stages command output and collected data in files before exfiltration.

T1074.001
Local Data Staging
MalwareNavRAT

NavRAT writes multiple outputs to a TMP file using the >> method.

T1074.001
Local Data Staging
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can store captured screenshots to disk including to a covert store named `APPX.%x%x%x%x%x.tmp` where `%x` is a random value.

T1074.001
Local Data Staging
MalwareChrommme

Chrommme can store captured system information locally prior to exfiltration.

T1074.001
Local Data Staging
MalwareObliqueRAT

ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories.

T1074.001
Local Data Staging
MalwareSocGholish

SocGholish can send output from `whoami` to a local temp file using the naming convention `rad<5-hex-chars>.tmp`.

T1074.001
Local Data Staging
MalwarePUNCHBUGGY

PUNCHBUGGY has saved information to a random temp file before exfil.

T1074.001
Local Data Staging
MalwarePteranodon

Pteranodon creates various subdirectories under %Temp%\reports\% and copies files to those subdirectories. It also creates a folder at C:\Users\<Username>\AppData\Roaming\Microsoft\store to store screenshot JPEG files.

T1074.001
Local Data Staging
MalwareBeaverTail

BeaverTail has staged collected data to the system’s temporary directory.

T1074.001
Local Data Staging
MalwareDarkWatchman

DarkWatchman can stage local data in the Windows Registry.

T1074.001
Local Data Staging
MalwareDyre

Dyre has the ability to create files in a TEMP folder to act as a database to store information.

T1074.001
Local Data Staging
MalwarePACEMAKER

PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`.

T1074.001
Local Data Staging
MalwarePlugX

PlugX has collected and staged the victim’s computer files for exfiltration.

T1074.001
Local Data Staging
MalwareLumma Stealer

Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data.

T1074.001
Local Data Staging
MalwareDustySky

DustySky created folders in temp directories to host collected files before exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.