Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareKeyBoy | KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1016 System Network Configuration Discovery |
MalwareKeyBoy | KeyBoy can determine the public or WAN IP address for the system. |
| T1027.013 Encrypted/Encoded File |
MalwareKeyBoy | In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware. |
| T1056.001 Keylogging |
MalwareKeyBoy | KeyBoy installs a keylogger for intercepting credentials and keystrokes. |
| T1059.001 PowerShell |
MalwareKeyBoy | KeyBoy uses PowerShell commands to download and execute payloads. |
| T1059.003 Windows Command Shell |
MalwareKeyBoy | KeyBoy can launch interactive shells for communicating with the victim machine. |
| T1059.005 Visual Basic |
MalwareKeyBoy | KeyBoy uses VBS scripts for installing files and performing execution. |
| T1059.006 Python |
MalwareKeyBoy | KeyBoy uses Python scripts for installing files and performing execution. |
| T1070.006 Timestomp |
MalwareKeyBoy | KeyBoy time-stomped its DLL in order to evade detection. |
| T1082 System Information Discovery |
MalwareKeyBoy | KeyBoy can gather extended system information, such as information about the operating system and memory. |
| T1083 File and Directory Discovery |
MalwareKeyBoy | KeyBoy has a command to launch a file browser or explorer on the system. |
| T1105 Ingress Tool Transfer |
MalwareKeyBoy | KeyBoy has a download and upload functionality. |
| T1113 Screen Capture |
MalwareKeyBoy | KeyBoy has a command to perform screen grabbing. |
| T1543.003 Windows Service |
MalwareKeyBoy | KeyBoy installs a service pointing to a malicious DLL dropped to disk. |
| T1547.004 Winlogon Helper DLL |
MalwareKeyBoy | KeyBoy issues the command |
| T1555.003 Credentials from Web Browsers |
MalwareKeyBoy | KeyBoy attempts to collect passwords from browsers. |
| T1559.002 Dynamic Data Exchange |
MalwareKeyBoy | KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads. |
| T1564.003 Hidden Window |
MalwareKeyBoy | KeyBoy uses |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.