ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0434×

16 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
ToolImminent Monitor

Imminent Monitor has a module for performing remote desktop access.

T1027
Obfuscated Files or Information
ToolImminent Monitor

Imminent Monitor has encrypted the spearphish attachments to avoid detection from email gateways; the debugger also encrypts information before sending to the C2.

T1041
Exfiltration Over C2 Channel
ToolImminent Monitor

Imminent Monitor has uploaded a file containing debugger logs, network information and system information to the C2.

T1056.001
Keylogging
ToolImminent Monitor

Imminent Monitor has a keylogging module.

T1057
Process Discovery
ToolImminent Monitor

Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed.

T1059
Command and Scripting Interpreter
ToolImminent Monitor

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1070.004
File Deletion
ToolImminent Monitor

Imminent Monitor has deleted files related to its dynamic debugger feature.

T1083
File and Directory Discovery
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there.

T1106
Native API
ToolImminent Monitor

Imminent Monitor has leveraged CreateProcessW() call to execute the debugger.

T1123
Audio Capture
ToolImminent Monitor

Imminent Monitor has a remote microphone monitoring capability.

T1125
Video Capture
ToolImminent Monitor

Imminent Monitor has a remote webcam monitoring capability.

T1140
Deobfuscate/Decode Files or Information
ToolImminent Monitor

Imminent Monitor has decoded malware components that are then dropped to the system.

T1496.001
Compute Hijacking
ToolImminent Monitor

Imminent Monitor has the capability to run a cryptocurrency miner on the victim machine.

T1555.003
Credentials from Web Browsers
ToolImminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1564.001
Hidden Files and Directories
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to set the file attribute to hidden.

T1685
Disable or Modify Tools
ToolImminent Monitor

Imminent Monitor has a feature to disable Windows Task Manager.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.