Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareDyre | Dyre has the ability to identify running services on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareDyre | Dyre has the ability to identify network settings on a compromised host. |
| T1027.002 Software Packing |
MalwareDyre | Dyre has been delivered with encrypted resources and must be unpacked for execution. |
| T1033 System Owner/User Discovery |
MalwareDyre | Dyre has the ability to identify the users on a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwareDyre | Dyre has the ability to send information staged on a compromised host externally to C2. |
| T1053.005 Scheduled Task |
MalwareDyre | Dyre has the ability to achieve persistence by adding a new task in the task scheduler to run every minute. |
| T1055 Process Injection |
MalwareDyre | Dyre has the ability to directly inject its code into the web browser process. |
| T1055.001 Dynamic-link Library Injection |
MalwareDyre | Dyre injects into other processes to load modules. |
| T1071.001 Web Protocols |
MalwareDyre | Dyre uses HTTPS for C2 communications. |
| T1074.001 Local Data Staging |
MalwareDyre | Dyre has the ability to create files in a TEMP folder to act as a database to store information. |
| T1082 System Information Discovery |
MalwareDyre | Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDyre | Dyre has a command to download and executes additional files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDyre | Dyre decrypts resources needed for targeting the victim. |
| T1497.001 System Checks |
MalwareDyre | Dyre can detect sandbox analysis environments by inspecting the process list and Registry. |
| T1518 Software Discovery |
MalwareDyre | Dyre has the ability to identify installed programs on a compromised host. |
| T1543.003 Windows Service |
MalwareDyre | Dyre registers itself as a service by adding several Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.