ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0184×

20 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarePOWRUNER

POWRUNER may query the Registry by running reg query on a victim.

T1016
System Network Configuration Discovery
MalwarePOWRUNER

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1033
System Owner/User Discovery
MalwarePOWRUNER

POWRUNER may collect information about the currently logged in user by running whoami on a victim.

T1047
Windows Management Instrumentation
MalwarePOWRUNER

POWRUNER may use WMI when collecting information about a victim.

T1049
System Network Connections Discovery
MalwarePOWRUNER

POWRUNER may collect active network connections by running netstat -an on a victim.

T1053.005
Scheduled Task
MalwarePOWRUNER

POWRUNER persists through a scheduled task that executes it every minute.

T1057
Process Discovery
MalwarePOWRUNER

POWRUNER may collect process information by running tasklist on a victim.

T1059.001
PowerShell
MalwarePOWRUNER

POWRUNER is written in PowerShell.

T1059.003
Windows Command Shell
MalwarePOWRUNER

POWRUNER can execute commands from its C2 server.

T1069.001
Local Groups
MalwarePOWRUNER

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.002
Domain Groups
MalwarePOWRUNER

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1071.001
Web Protocols
MalwarePOWRUNER

POWRUNER can use HTTP for C2 communications.

T1071.004
DNS
MalwarePOWRUNER

POWRUNER can use DNS for C2 communications.

T1082
System Information Discovery
MalwarePOWRUNER

POWRUNER may collect information about the system by running hostname and systeminfo on a victim.

T1083
File and Directory Discovery
MalwarePOWRUNER

POWRUNER may enumerate user directories on a victim.

T1087.002
Domain Account
MalwarePOWRUNER

POWRUNER may collect user account information by running net user /domain or a series of other commands on a victim.

T1105
Ingress Tool Transfer
MalwarePOWRUNER

POWRUNER can download or upload files from its C2 server.

T1113
Screen Capture
MalwarePOWRUNER

POWRUNER can capture a screenshot from a victim.

T1132.001
Standard Encoding
MalwarePOWRUNER

POWRUNER can use base64 encoded C2 communications.

T1518.001
Security Software Discovery
MalwarePOWRUNER

POWRUNER may collect information on the victim's anti-virus software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.