Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMachete | Machete searches the File system for files of interest. |
| T1008 Fallback Channels |
MalwareMachete | Machete has sent data over HTTP if FTP failed, and has also used a fallback server. |
| T1010 Application Window Discovery |
MalwareMachete | Machete saves the window names. |
| T1016 System Network Configuration Discovery |
MalwareMachete | Machete collects the MAC address of the target computer and other network configuration information. |
| T1016.002 Wi-Fi Discovery |
MalwareMachete | Machete uses the |
| T1020 Automated Exfiltration |
MalwareMachete | Machete’s collected files are exfiltrated automatically to remote servers. |
| T1025 Data from Removable Media |
MalwareMachete | Machete can find, encrypt, and upload files from fixed and removable drives. |
| T1027.002 Software Packing |
MalwareMachete | Machete has been packed with NSIS. |
| T1027.010 Command Obfuscation |
MalwareMachete | Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis. |
| T1029 Scheduled Transfer |
MalwareMachete | Machete sends stolen data to the C2 server every 10 minutes. |
| T1036.004 Masquerade Task or Service |
MalwareMachete | Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMachete | Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables. |
| T1041 Exfiltration Over C2 Channel |
MalwareMachete | Machete's collected data is exfiltrated over the same channel used for C2. |
| T1052.001 Exfiltration over USB |
MalwareMachete | Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| T1053.005 Scheduled Task |
MalwareMachete | The different components of Machete are executed by Windows Task Scheduler. |
| T1056.001 Keylogging |
MalwareMachete | Machete logs keystrokes from the victim’s machine. |
| T1057 Process Discovery |
MalwareMachete | Machete has a component to check for running processes to look for web browsers. |
| T1059.006 Python |
MalwareMachete | Machete is written in Python and is used in conjunction with additional Python scripts. |
| T1070.004 File Deletion |
MalwareMachete | Once a file is uploaded, Machete will delete it from the machine. |
| T1071.001 Web Protocols |
MalwareMachete | Machete uses HTTP for Command & Control. |
| T1071.002 File Transfer Protocols |
MalwareMachete | Machete uses FTP for Command & Control. |
| T1074.001 Local Data Staging |
MalwareMachete | Machete stores files and logs in a folder on the local drive. |
| T1082 System Information Discovery |
MalwareMachete | Machete collects the hostname of the target computer. |
| T1083 File and Directory Discovery |
MalwareMachete | Machete produces file listings in order to search for files to be exfiltrated. |
| T1105 Ingress Tool Transfer |
MalwareMachete | Machete can download additional files for execution on the victim’s machine. |
| T1113 Screen Capture |
MalwareMachete | Machete captures screenshots. |
| T1115 Clipboard Data |
MalwareMachete | Machete hijacks the clipboard data by creating an overlapped window that listens to keyboard events. |
| T1120 Peripheral Device Discovery |
MalwareMachete | Machete detects the insertion of new devices by listening for the WM_DEVICECHANGE window message. |
| T1123 Audio Capture |
MalwareMachete | Machete captures audio from the computer’s microphone. |
| T1125 Video Capture |
MalwareMachete | Machete takes photos from the computer’s web camera. |
| T1132.001 Standard Encoding |
MalwareMachete | Machete has used base64 encoding. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMachete | Machete’s downloaded data is decrypted using AES. |
| T1217 Browser Information Discovery |
MalwareMachete | Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMachete | Machete used the startup folder for persistence. |
| T1552.004 Private Keys |
MalwareMachete | Machete has scanned and looked for cryptographic keys and certificate file extensions. |
| T1555.003 Credentials from Web Browsers |
MalwareMachete | Machete collects stored credentials from several web browsers. |
| T1560 Archive Collected Data |
MalwareMachete | Machete stores zipped files with profile data from installed web browsers. |
| T1560.003 Archive via Custom Method |
MalwareMachete | Machete's collected data is encrypted with AES before exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareMachete | Machete has the capability to exfiltrate stolen data to a hidden folder on a removable drive. |
| T1573.001 Symmetric Cryptography |
MalwareMachete | Machete has used AES to exfiltrate documents. |
| T1573.002 Asymmetric Cryptography |
MalwareMachete | Machete has used TLS-encrypted FTP to exfiltrate data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.