Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
MalwareDarkComet | DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard. |
| T1027.002 Software Packing |
MalwareDarkComet | DarkComet has the option to compress its payload using UPX or MPRESS. |
| T1033 System Owner/User Discovery |
MalwareDarkComet | DarkComet gathers the username from the victim’s machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDarkComet | DarkComet has dropped itself onto victim machines with file names such as WinDefender.Exe and winupdate.exe in an apparent attempt to masquerade as a legitimate file. |
| T1056.001 Keylogging |
MalwareDarkComet | DarkComet has a keylogging capability. |
| T1057 Process Discovery |
MalwareDarkComet | DarkComet can list active processes running on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareDarkComet | DarkComet can execute various types of scripts on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareDarkComet | DarkComet can launch a remote shell to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareDarkComet | DarkComet can use HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareDarkComet | DarkComet can collect the computer name, RAM used, and operating system version from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareDarkComet | DarkComet can load any files onto the infected machine to execute. |
| T1112 Modify Registry |
MalwareDarkComet | DarkComet adds a Registry value for its installation routine to the Registry Key |
| T1115 Clipboard Data |
MalwareDarkComet | DarkComet can steal data from the clipboard. |
| T1123 Audio Capture |
MalwareDarkComet | DarkComet can listen in to victims' conversations through the system’s microphone. |
| T1125 Video Capture |
MalwareDarkComet | DarkComet can access the victim’s webcam to take pictures. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkComet | DarkComet adds several Registry entries to enable automatic execution at every system startup. |
| T1685 Disable or Modify Tools |
MalwareDarkComet | DarkComet can disable Security Center functions like anti-virus. |
| T1686.003 Windows Host Firewall |
MalwareDarkComet | DarkComet can disable Security Center functions like the Windows Firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.