ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0340×

19 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOctopus

Octopus can exfiltrate files from the system using a documents collector tool.

T1016
System Network Configuration Discovery
MalwareOctopus

Octopus can collect the host IP address from the victim’s machine.

T1033
System Owner/User Discovery
MalwareOctopus

Octopus can collect the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1041
Exfiltration Over C2 Channel
MalwareOctopus

Octopus has uploaded stolen files and data from a victim's machine over its C2 channel.

T1047
Windows Management Instrumentation
MalwareOctopus

Octopus has used wmic.exe for local discovery information.

T1071.001
Web Protocols
MalwareOctopus

Octopus has used HTTP GET and POST requests for C2 communications.

T1074.001
Local Data Staging
MalwareOctopus

Octopus has stored collected information in the Application Data directory on a compromised host.

T1082
System Information Discovery
MalwareOctopus

Octopus can collect the computer name, OS version, and OS architecture information.

T1083
File and Directory Discovery
MalwareOctopus

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1105
Ingress Tool Transfer
MalwareOctopus

Octopus can download additional files and tools onto the victim’s machine.

T1113
Screen Capture
MalwareOctopus

Octopus can capture screenshots of the victims’ machine.

T1132.001
Standard Encoding
MalwareOctopus

Octopus has encoded C2 communications in Base64.

T1204.002
Malicious File
MalwareOctopus

Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1547.001
Registry Run Keys / Startup Folder
MalwareOctopus

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

T1560.001
Archive via Utility
MalwareOctopus

Octopus has compressed data before exfiltrating it using a tool called Abbrevia.

T1566.001
Spearphishing Attachment
MalwareOctopus

Octopus has been delivered via spearsphishing emails.

T1567.002
Exfiltration to Cloud Storage
MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

T1680
Local Storage Discovery
MalwareOctopus

Octopus can collect system drive and disk size information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.