Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareBabyShark | BabyShark has executed the |
| T1016 System Network Configuration Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1033 System Owner/User Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1053.005 Scheduled Task |
MalwareBabyShark | BabyShark has used scheduled tasks to maintain persistence. |
| T1056.001 Keylogging |
MalwareBabyShark | BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| T1057 Process Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1059.003 Windows Command Shell |
MalwareBabyShark | BabyShark has used cmd.exe to execute commands. |
| T1059.005 Visual Basic |
MalwareBabyShark | BabyShark can execute additional VisualBasic content. |
| T1070.004 File Deletion |
MalwareBabyShark | BabyShark has cleaned up all files associated with the secondary payload execution. |
| T1082 System Information Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1083 File and Directory Discovery |
MalwareBabyShark | BabyShark has used |
| T1105 Ingress Tool Transfer |
MalwareBabyShark | BabyShark has downloaded additional files from the C2. |
| T1132.001 Standard Encoding |
MalwareBabyShark | BabyShark has encoded data using certutil before exfiltration. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBabyShark | BabyShark has the ability to decode downloaded files prior to execution. |
| T1218.005 Mshta |
MalwareBabyShark | BabyShark has used mshta.exe to download and execute applications from a remote server. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBabyShark | BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.