Real-world descriptions of how a group, tool or campaign used a technique.
24 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSDBbot | SDBbot has the ability to access the file system on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareSDBbot | SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host. |
| T1021.001 Remote Desktop Protocol |
MalwareSDBbot | SDBbot has the ability to use RDP to connect to victim's machines. |
| T1027 Obfuscated Files or Information |
MalwareSDBbot | SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key. |
| T1027.002 Software Packing |
MalwareSDBbot | SDBbot has used a packed installer file. |
| T1033 System Owner/User Discovery |
MalwareSDBbot | SDBbot has the ability to identify the user on a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwareSDBbot | SDBbot has sent collected data from a compromised host to its C2 servers. |
| T1055.001 Dynamic-link Library Injection |
MalwareSDBbot | SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process. |
| T1057 Process Discovery |
MalwareSDBbot | SDBbot can enumerate a list of running processes on a compromised machine. |
| T1059.003 Windows Command Shell |
MalwareSDBbot | SDBbot has the ability to use the command shell to execute commands on a compromised host. |
| T1070 Indicator Removal |
MalwareSDBbot | SDBbot has the ability to clean up and remove data structures from a compromised host. |
| T1070.004 File Deletion |
MalwareSDBbot | SDBbot has the ability to delete files from a compromised host. |
| T1082 System Information Discovery |
MalwareSDBbot | SDBbot has the ability to identify the OS version, OS bit information and computer name. |
| T1083 File and Directory Discovery |
MalwareSDBbot | SDBbot has the ability to get directory listings or drive information on a compromised host. |
| T1090 Proxy |
MalwareSDBbot | SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2. |
| T1095 Non-Application Layer Protocol |
MalwareSDBbot | SDBbot has the ability to communicate with C2 with TCP over port 443. |
| T1105 Ingress Tool Transfer |
MalwareSDBbot | SDBbot has the ability to download a DLL from C2 to a compromised host. |
| T1125 Video Capture |
MalwareSDBbot | SDBbot has the ability to record video on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSDBbot | SDBbot has the ability to decrypt and decompress its payload to enable code execution. |
| T1218.011 Rundll32 |
MalwareSDBbot | SDBbot has used rundll32.exe to execute DLLs. |
| T1546.011 Application Shimming |
MalwareSDBbot | SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe. |
| T1546.012 Image File Execution Options Injection |
MalwareSDBbot | SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSDBbot | SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege. |
| T1614 System Location Discovery |
MalwareSDBbot | SDBbot can collected the country code of a compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.