Real-world descriptions of how a group, tool or campaign used a technique.
37 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAgent Tesla | Agent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings. |
| T1016.002 Wi-Fi Discovery |
MalwareAgent Tesla | Agent Tesla can collect names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1027 Obfuscated Files or Information |
MalwareAgent Tesla | Agent Tesla has had its code obfuscated in an apparent attempt to make analysis difficult. Agent Tesla has used the Rijndael symmetric encryption algorithm to encrypt strings. |
| T1033 System Owner/User Discovery |
MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| T1047 Windows Management Instrumentation |
MalwareAgent Tesla | Agent Tesla has used wmi queries to gather information from the system. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1053.005 Scheduled Task |
MalwareAgent Tesla | Agent Tesla has achieved persistence via scheduled tasks. |
| T1055 Process Injection |
MalwareAgent Tesla | Agent Tesla can inject into known, vulnerable binaries on targeted hosts. |
| T1055.012 Process Hollowing |
MalwareAgent Tesla | Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1057 Process Discovery |
MalwareAgent Tesla | Agent Tesla can list the current running processes on the system. |
| T1071.001 Web Protocols |
MalwareAgent Tesla | Agent Tesla has used HTTP for C2 communications. |
| T1071.003 Mail Protocols |
MalwareAgent Tesla | Agent Tesla has used SMTP for C2 communications. |
| T1082 System Information Discovery |
MalwareAgent Tesla | Agent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system. |
| T1087.001 Local Account |
MalwareAgent Tesla | Agent Tesla can collect account information from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareAgent Tesla | Agent Tesla can download additional files for execution on the victim’s machine. |
| T1112 Modify Registry |
MalwareAgent Tesla | Agent Tesla can achieve persistence by modifying Registry key entries. |
| T1113 Screen Capture |
MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| T1115 Clipboard Data |
MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| T1124 System Time Discovery |
MalwareAgent Tesla | Agent Tesla can collect the timestamp from the victim’s machine. |
| T1125 Video Capture |
MalwareAgent Tesla | Agent Tesla can access the victim’s webcam and record video. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAgent Tesla | Agent Tesla has the ability to decrypt strings encrypted with the Rijndael symmetric encryption algorithm. |
| T1185 Browser Session Hijacking |
MalwareAgent Tesla | Agent Tesla has the ability to use form-grabbing to extract data from web data forms. |
| T1203 Exploitation for Client Execution |
MalwareAgent Tesla | Agent Tesla has exploited Office vulnerabilities such as CVE-2017-11882 and CVE-2017-8570 for execution during delivery. |
| T1204.002 Malicious File |
MalwareAgent Tesla | Agent Tesla has been executed through malicious e-mail attachments |
| T1218.009 Regsvcs/Regasm |
MalwareAgent Tesla | Agent Tesla has dropped RegAsm.exe onto systems for performing malicious activity. |
| T1497 Virtualization/Sandbox Evasion |
MalwareAgent Tesla | Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAgent Tesla | Agent Tesla can add itself to the Registry as a startup program to establish persistence. |
| T1552.001 Credentials In Files |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from configuration or support files. |
| T1552.002 Credentials in Registry |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from the Registry. |
| T1555 Credentials from Password Stores |
MalwareAgent Tesla | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles. |
| T1555.003 Credentials from Web Browsers |
MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
| T1560 Archive Collected Data |
MalwareAgent Tesla | Agent Tesla can encrypt data with 3DES before sending it over to a C2 server. |
| T1564.001 Hidden Files and Directories |
MalwareAgent Tesla | Agent Tesla has created hidden folders. |
| T1564.003 Hidden Window |
MalwareAgent Tesla | Agent Tesla has used |
| T1566.001 Spearphishing Attachment |
MalwareAgent Tesla | The primary delivered mechanism for Agent Tesla is through email phishing messages. |
| T1685 Disable or Modify Tools |
MalwareAgent Tesla | Agent Tesla has the capability to kill any running analysis processes and AV software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.