ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0431×

20 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of services on the infected host.

T1010
Application Window Discovery
MalwareHotCroissant

HotCroissant has the ability to list the names of all open windows on the infected host.

T1016
System Network Configuration Discovery
MalwareHotCroissant

HotCroissant has the ability to identify the IP address of the compromised machine.

T1027.002
Software Packing
MalwareHotCroissant

HotCroissant has used the open source UPX executable packer.

T1027.013
Encrypted/Encoded File
MalwareHotCroissant

HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4.

T1033
System Owner/User Discovery
MalwareHotCroissant

HotCroissant has the ability to collect the username on the infected host.

T1041
Exfiltration Over C2 Channel
MalwareHotCroissant

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1053.005
Scheduled Task
MalwareHotCroissant

HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence.

T1057
Process Discovery
MalwareHotCroissant

HotCroissant has the ability to list running processes on the infected host.

T1059.003
Windows Command Shell
MalwareHotCroissant

HotCroissant can remotely open applications on the infected host with the ShellExecuteA command.

T1070.004
File Deletion
MalwareHotCroissant

HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine.

T1082
System Information Discovery
MalwareHotCroissant

HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host.

T1083
File and Directory Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types.

T1105
Ingress Tool Transfer
MalwareHotCroissant

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.

T1106
Native API
MalwareHotCroissant

HotCroissant can perform dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings.

T1113
Screen Capture
MalwareHotCroissant

HotCroissant has the ability to do real time screen viewing on an infected host.

T1489
Service Stop
MalwareHotCroissant

HotCroissant has the ability to stop services on the infected host.

T1518
Software Discovery
MalwareHotCroissant

HotCroissant can retrieve a list of applications from the SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths registry key.

T1564.003
Hidden Window
MalwareHotCroissant

HotCroissant has the ability to hide the window for operations performed on a given file.

T1573.001
Symmetric Cryptography
MalwareHotCroissant

HotCroissant has compressed network communications and encrypted them with a custom stream cipher.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.