ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0461×

24 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSDBbot

SDBbot has the ability to access the file system on a compromised host.

T1016
System Network Configuration Discovery
MalwareSDBbot

SDBbot has the ability to determine the domain name and whether a proxy is configured on a compromised host.

T1021.001
Remote Desktop Protocol
MalwareSDBbot

SDBbot has the ability to use RDP to connect to victim's machines.

T1027
Obfuscated Files or Information
MalwareSDBbot

SDBbot has the ability to XOR the strings for its installer component with a hardcoded 128 byte key.

T1027.002
Software Packing
MalwareSDBbot

SDBbot has used a packed installer file.

T1033
System Owner/User Discovery
MalwareSDBbot

SDBbot has the ability to identify the user on a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareSDBbot

SDBbot has sent collected data from a compromised host to its C2 servers.

T1055.001
Dynamic-link Library Injection
MalwareSDBbot

SDBbot has the ability to inject a downloaded DLL into a newly created rundll32.exe process.

T1057
Process Discovery
MalwareSDBbot

SDBbot can enumerate a list of running processes on a compromised machine.

T1059.003
Windows Command Shell
MalwareSDBbot

SDBbot has the ability to use the command shell to execute commands on a compromised host.

T1070
Indicator Removal
MalwareSDBbot

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070.004
File Deletion
MalwareSDBbot

SDBbot has the ability to delete files from a compromised host.

T1082
System Information Discovery
MalwareSDBbot

SDBbot has the ability to identify the OS version, OS bit information and computer name.

T1083
File and Directory Discovery
MalwareSDBbot

SDBbot has the ability to get directory listings or drive information on a compromised host.

T1090
Proxy
MalwareSDBbot

SDBbot has the ability to use port forwarding to establish a proxy between a target host and C2.

T1095
Non-Application Layer Protocol
MalwareSDBbot

SDBbot has the ability to communicate with C2 with TCP over port 443.

T1105
Ingress Tool Transfer
MalwareSDBbot

SDBbot has the ability to download a DLL from C2 to a compromised host.

T1125
Video Capture
MalwareSDBbot

SDBbot has the ability to record video on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareSDBbot

SDBbot has the ability to decrypt and decompress its payload to enable code execution.

T1218.011
Rundll32
MalwareSDBbot

SDBbot has used rundll32.exe to execute DLLs.

T1546.011
Application Shimming
MalwareSDBbot

SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe.

T1546.012
Image File Execution Options Injection
MalwareSDBbot

SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7.

T1547.001
Registry Run Keys / Startup Folder
MalwareSDBbot

SDBbot has the ability to add a value to the Registry Run key to establish persistence if it detects it is running with regular user privilege.

T1614
System Location Discovery
MalwareSDBbot

SDBbot can collected the country code of a compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.