Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host. |
| T1020 Automated Exfiltration |
ToolShimRatReporter | ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2. |
| T1027 Obfuscated Files or Information |
ToolShimRatReporter | ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolShimRatReporter | ShimRatReporter spoofed itself as |
| T1041 Exfiltration Over C2 Channel |
ToolShimRatReporter | ShimRatReporter sent generated reports to the C2 via HTTP POST requests. |
| T1049 System Network Connections Discovery |
ToolShimRatReporter | ShimRatReporter used the Windows function |
| T1057 Process Discovery |
ToolShimRatReporter | ShimRatReporter listed all running processes on the machine. |
| T1069 Permission Groups Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local privileges for the infected host. |
| T1071.001 Web Protocols |
ToolShimRatReporter | ShimRatReporter communicated over HTTP with preconfigured C2 servers. |
| T1082 System Information Discovery |
ToolShimRatReporter | ShimRatReporter gathered the operating system name and specific Windows version of an infected machine. |
| T1087 Account Discovery |
ToolShimRatReporter | ShimRatReporter listed all non-privileged and privileged accounts available on the machine. |
| T1105 Ingress Tool Transfer |
ToolShimRatReporter | ShimRatReporter had the ability to download additional payloads. |
| T1106 Native API |
ToolShimRatReporter | ShimRatReporter used several Windows API functions to gather information from the infected system. |
| T1119 Automated Collection |
ToolShimRatReporter | ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators. |
| T1518 Software Discovery |
ToolShimRatReporter | ShimRatReporter gathered a list of installed software on the infected host. |
| T1560 Archive Collected Data |
ToolShimRatReporter | ShimRatReporter used LZ compression to compress initial reconnaissance reports before sending to the C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.