Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
ToolKoadic | Koadic can gather hashed passwords by dumping SAM/SECURITY hive. |
| T1003.003 NTDS |
ToolKoadic | Koadic can gather hashed passwords by gathering domain controller hashes from NTDS. |
| T1005 Data from Local System |
ToolKoadic | Koadic can download files off the target system to send back to the server. |
| T1016 System Network Configuration Discovery |
ToolKoadic | Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain. |
| T1021.001 Remote Desktop Protocol |
ToolKoadic | Koadic can enable remote desktop on the victim's machine. |
| T1033 System Owner/User Discovery |
ToolKoadic | Koadic can identify logged in users across the domain and views user sessions. |
| T1046 Network Service Discovery |
ToolKoadic | Koadic can scan for open TCP ports on the target network. |
| T1047 Windows Management Instrumentation |
ToolKoadic | Koadic can use WMI to execute commands. |
| T1053.005 Scheduled Task |
ToolKoadic | Koadic has used scheduled tasks to add persistence. |
| T1055.001 Dynamic-link Library Injection |
ToolKoadic | Koadic can perform process injection by using a reflective DLL. |
| T1059.001 PowerShell |
ToolKoadic | Koadic has used PowerShell to establish persistence. |
| T1059.003 Windows Command Shell |
ToolKoadic | Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.005 Visual Basic |
ToolKoadic | Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode . |
| T1071.001 Web Protocols |
ToolKoadic | Koadic has used HTTP for C2 communications. |
| T1082 System Information Discovery |
ToolKoadic | Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host. |
| T1083 File and Directory Discovery |
ToolKoadic | Koadic can obtain a list of directories. |
| T1105 Ingress Tool Transfer |
ToolKoadic | Koadic can download additional files and tools. |
| T1115 Clipboard Data |
ToolKoadic | Koadic can retrieve the current content of the user clipboard. |
| T1135 Network Share Discovery |
ToolKoadic | Koadic can scan local network for open SMB. |
| T1218.005 Mshta |
ToolKoadic | Koadic can use mshta to serve additional payloads and to help schedule tasks for persistence. |
| T1218.010 Regsvr32 |
ToolKoadic | Koadic can use Regsvr32 to execute additional payloads. |
| T1218.011 Rundll32 |
ToolKoadic | Koadic can use Rundll32 to execute additional payloads. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolKoadic | Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key. |
| T1548.002 Bypass User Account Control |
ToolKoadic | Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`. |
| T1564.003 Hidden Window |
ToolKoadic | Koadic has used the command |
| T1569.002 Service Execution |
ToolKoadic | |
| T1573.002 Asymmetric Cryptography |
ToolKoadic | Koadic can use SSL and TLS for communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.