ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0024×

16 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareDyre

Dyre has the ability to identify running services on a compromised host.

T1016
System Network Configuration Discovery
MalwareDyre

Dyre has the ability to identify network settings on a compromised host.

T1027.002
Software Packing
MalwareDyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1033
System Owner/User Discovery
MalwareDyre

Dyre has the ability to identify the users on a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareDyre

Dyre has the ability to send information staged on a compromised host externally to C2.

T1053.005
Scheduled Task
MalwareDyre

Dyre has the ability to achieve persistence by adding a new task in the task scheduler to run every minute.

T1055
Process Injection
MalwareDyre

Dyre has the ability to directly inject its code into the web browser process.

T1055.001
Dynamic-link Library Injection
MalwareDyre

Dyre injects into other processes to load modules.

T1071.001
Web Protocols
MalwareDyre

Dyre uses HTTPS for C2 communications.

T1074.001
Local Data Staging
MalwareDyre

Dyre has the ability to create files in a TEMP folder to act as a database to store information.

T1082
System Information Discovery
MalwareDyre

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.

T1105
Ingress Tool Transfer
MalwareDyre

Dyre has a command to download and executes additional files.

T1140
Deobfuscate/Decode Files or Information
MalwareDyre

Dyre decrypts resources needed for targeting the victim.

T1497.001
System Checks
MalwareDyre

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1518
Software Discovery
MalwareDyre

Dyre has the ability to identify installed programs on a compromised host.

T1543.003
Windows Service
MalwareDyre

Dyre registers itself as a service by adding several Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.