Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareGreyEnergy | GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| T1007 System Service Discovery |
MalwareGreyEnergy | GreyEnergy enumerates all Windows services. |
| T1027.002 Software Packing |
MalwareGreyEnergy | GreyEnergy is packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareGreyEnergy | GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings. |
| T1055.002 Portable Executable Injection |
MalwareGreyEnergy | GreyEnergy has a module to inject a PE binary into a remote process. |
| T1056.001 Keylogging |
MalwareGreyEnergy | GreyEnergy has a module to harvest pressed keystrokes. |
| T1059.003 Windows Command Shell |
MalwareGreyEnergy | GreyEnergy uses cmd.exe to execute itself in-memory. |
| T1070.004 File Deletion |
MalwareGreyEnergy | GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API. |
| T1071.001 Web Protocols |
MalwareGreyEnergy | GreyEnergy uses HTTP and HTTPS for C2 communications. |
| T1090.003 Multi-hop Proxy |
MalwareGreyEnergy | GreyEnergy has used Tor relays for Command and Control servers. |
| T1105 Ingress Tool Transfer |
MalwareGreyEnergy | GreyEnergy can download additional modules and payloads. |
| T1112 Modify Registry |
MalwareGreyEnergy | GreyEnergy modifies conditions in the Registry and adds keys. |
| T1218.011 Rundll32 |
MalwareGreyEnergy | GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM). |
| T1543.003 Windows Service |
MalwareGreyEnergy | GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key. |
| T1553.002 Code Signing |
MalwareGreyEnergy | GreyEnergy digitally signs the malware with a code-signing certificate. |
| T1573.001 Symmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using AES256. |
| T1573.002 Asymmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using RSA-2048. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.