ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0250×

27 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
ToolKoadic

Koadic can gather hashed passwords by dumping SAM/SECURITY hive.

T1003.003
NTDS
ToolKoadic

Koadic can gather hashed passwords by gathering domain controller hashes from NTDS.

T1005
Data from Local System
ToolKoadic

Koadic can download files off the target system to send back to the server.

T1016
System Network Configuration Discovery
ToolKoadic

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1021.001
Remote Desktop Protocol
ToolKoadic

Koadic can enable remote desktop on the victim's machine.

T1033
System Owner/User Discovery
ToolKoadic

Koadic can identify logged in users across the domain and views user sessions.

T1046
Network Service Discovery
ToolKoadic

Koadic can scan for open TCP ports on the target network.

T1047
Windows Management Instrumentation
ToolKoadic

Koadic can use WMI to execute commands.

T1053.005
Scheduled Task
ToolKoadic

Koadic has used scheduled tasks to add persistence.

T1055.001
Dynamic-link Library Injection
ToolKoadic

Koadic can perform process injection by using a reflective DLL.

T1059.001
PowerShell
ToolKoadic

Koadic has used PowerShell to establish persistence.

T1059.003
Windows Command Shell
ToolKoadic

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.005
Visual Basic
ToolKoadic

Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode .

T1071.001
Web Protocols
ToolKoadic

Koadic has used HTTP for C2 communications.

T1082
System Information Discovery
ToolKoadic

Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host.

T1083
File and Directory Discovery
ToolKoadic

Koadic can obtain a list of directories.

T1105
Ingress Tool Transfer
ToolKoadic

Koadic can download additional files and tools.

T1115
Clipboard Data
ToolKoadic

Koadic can retrieve the current content of the user clipboard.

T1135
Network Share Discovery
ToolKoadic

Koadic can scan local network for open SMB.

T1218.005
Mshta
ToolKoadic

Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence.

T1218.010
Regsvr32
ToolKoadic

Koadic can use Regsvr32 to execute additional payloads.

T1218.011
Rundll32
ToolKoadic

Koadic can use Rundll32 to execute additional payloads.

T1547.001
Registry Run Keys / Startup Folder
ToolKoadic

Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key.

T1548.002
Bypass User Account Control
ToolKoadic

Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`.

T1564.003
Hidden Window
ToolKoadic

Koadic has used the command Powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden to hide its window.

T1569.002
Service Execution
ToolKoadic

Koadic can run a command on another machine using PsExec.

T1573.002
Asymmetric Cryptography
ToolKoadic

Koadic can use SSL and TLS for communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.