Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareDenis | Denis queries the Registry for keys and values. |
| T1016 System Network Configuration Discovery |
MalwareDenis | Denis uses |
| T1027 Obfuscated Files or Information |
MalwareDenis | Denis obfuscates its code and encrypts the API names. |
| T1027.010 Command Obfuscation |
MalwareDenis | Denis has encoded its PowerShell commands in Base64. |
| T1033 System Owner/User Discovery |
MalwareDenis | Denis enumerates and collects the username from the victim’s machine. |
| T1055.012 Process Hollowing |
MalwareDenis | Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1059.001 PowerShell |
MalwareDenis | Denis has a version written in PowerShell. |
| T1059.003 Windows Command Shell |
MalwareDenis | Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1070.004 File Deletion |
MalwareDenis | Denis has a command to delete files from the victim’s machine. |
| T1071.004 DNS |
MalwareDenis | Denis has used DNS tunneling for C2 communications. |
| T1082 System Information Discovery |
MalwareDenis | Denis collects OS information and the computer name from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareDenis | Denis has several commands to search directories for files. |
| T1105 Ingress Tool Transfer |
MalwareDenis | Denis deploys additional backdoors and hacking tools to the system. |
| T1106 Native API |
MalwareDenis | Denis used the |
| T1132.001 Standard Encoding |
MalwareDenis | Denis encodes the data sent to the server in Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDenis | Denis will decrypt important strings used for C&C communication. |
| T1497.001 System Checks |
MalwareDenis | Denis ran multiple system checks, looking for processor and register characteristics, to evade emulation and analysis. |
| T1560.002 Archive via Library |
MalwareDenis | Denis compressed collected data using zlib. |
| T1574 Hijack Execution Flow |
MalwareDenis | Denis replaces the nonexistent Windows DLL "msfte.dll" with its own malicious version, which is loaded by the SearchIndexer.exe and SearchProtocolHost.exe. |
| T1574.001 DLL |
MalwareDenis | Denis exploits a security vulnerability to load a fake DLL and execute its code. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.