Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareS-Type | S-Type runs the command |
| T1008 Fallback Channels |
MalwareS-Type | S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails. |
| T1016 System Network Configuration Discovery |
MalwareS-Type | S-Type has used `ipconfig /all` on a compromised host. |
| T1027.002 Software Packing |
MalwareS-Type | Some S-Type samples have been packed with UPX. |
| T1033 System Owner/User Discovery |
MalwareS-Type | S-Type has run tests to determine the privilege level of the compromised user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareS-Type | S-Type may save itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary. |
| T1041 Exfiltration Over C2 Channel |
MalwareS-Type | S-Type has uploaded data and files from a compromised host to its C2 servers. |
| T1059.003 Windows Command Shell |
MalwareS-Type | S-Type has provided the ability to execute shell commands on a compromised host. |
| T1070.004 File Deletion |
MalwareS-Type | S-Type has deleted files it has created on a compromised host. |
| T1070.009 Clear Persistence |
MalwareS-Type | S-Type has deleted accounts it has created. |
| T1071.001 Web Protocols |
MalwareS-Type | S-Type uses HTTP for C2. |
| T1082 System Information Discovery |
MalwareS-Type | The initial beacon packet for S-Type contains the operating system version and file system of the victim. |
| T1087.001 Local Account |
MalwareS-Type | S-Type has run the command `net user` on a victim. |
| T1105 Ingress Tool Transfer |
MalwareS-Type | S-Type can download additional files onto a compromised host. |
| T1106 Native API |
MalwareS-Type | S-Type has used Windows APIs, including `GetKeyboardType`, `NetUserAdd`, and `NetUserDel`. |
| T1132.001 Standard Encoding |
MalwareS-Type | S-Type uses Base64 encoding for C2 traffic. |
| T1136.001 Local Account |
MalwareS-Type | S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareS-Type | S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key |
| T1547.009 Shortcut Modification |
MalwareS-Type | S-Type may create the file |
| T1614.001 System Language Discovery |
MalwareS-Type | S-Type has attempted to determine if a compromised system was using a Japanese keyboard via the `GetKeyboardType` API call. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.