Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of services on the infected host. |
| T1010 Application Window Discovery |
MalwareHotCroissant | HotCroissant has the ability to list the names of all open windows on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareHotCroissant | HotCroissant has the ability to identify the IP address of the compromised machine. |
| T1027.002 Software Packing |
MalwareHotCroissant | HotCroissant has used the open source UPX executable packer. |
| T1027.013 Encrypted/Encoded File |
MalwareHotCroissant | HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4. |
| T1033 System Owner/User Discovery |
MalwareHotCroissant | HotCroissant has the ability to collect the username on the infected host. |
| T1041 Exfiltration Over C2 Channel |
MalwareHotCroissant | HotCroissant has the ability to download files from the infected host to the command and control (C2) server. |
| T1053.005 Scheduled Task |
MalwareHotCroissant | HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence. |
| T1057 Process Discovery |
MalwareHotCroissant | HotCroissant has the ability to list running processes on the infected host. |
| T1059.003 Windows Command Shell |
MalwareHotCroissant | HotCroissant can remotely open applications on the infected host with the |
| T1070.004 File Deletion |
MalwareHotCroissant | HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine. |
| T1082 System Information Discovery |
MalwareHotCroissant | HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host. |
| T1083 File and Directory Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1105 Ingress Tool Transfer |
MalwareHotCroissant | HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine. |
| T1106 Native API |
MalwareHotCroissant | HotCroissant can perform dynamic DLL importing and API lookups using |
| T1113 Screen Capture |
MalwareHotCroissant | HotCroissant has the ability to do real time screen viewing on an infected host. |
| T1489 Service Stop |
MalwareHotCroissant | HotCroissant has the ability to stop services on the infected host. |
| T1518 Software Discovery |
MalwareHotCroissant | HotCroissant can retrieve a list of applications from the |
| T1564.003 Hidden Window |
MalwareHotCroissant | HotCroissant has the ability to hide the window for operations performed on a given file. |
| T1573.001 Symmetric Cryptography |
MalwareHotCroissant | HotCroissant has compressed network communications and encrypted them with a custom stream cipher. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.