ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0504×

20 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareAnchor

Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1016
System Network Configuration Discovery
MalwareAnchor

Anchor can determine the public IP and location of a compromised host.

T1021.002
SMB/Windows Admin Shares
MalwareAnchor

Anchor can support windows execution via SMB shares.

T1027
Obfuscated Files or Information
MalwareAnchor

Anchor has obfuscated code with stack strings and string encryption.

T1027.002
Software Packing
MalwareAnchor

Anchor has come with a packed payload.

T1053.003
Cron
MalwareAnchor

Anchor can install itself as a cron job.

T1053.005
Scheduled Task
MalwareAnchor

Anchor can create a scheduled task for persistence.

T1059.003
Windows Command Shell
MalwareAnchor

Anchor has used cmd.exe to run its self deletion routine.

T1059.004
Unix Shell
MalwareAnchor

Anchor can execute payloads via shell scripting.

T1070.004
File Deletion
MalwareAnchor

Anchor can self delete its dropper after the malware is successfully deployed.

T1071.001
Web Protocols
MalwareAnchor

Anchor has used HTTP and HTTPS in C2 communications.

T1071.004
DNS
MalwareAnchor

Variants of Anchor can use DNS tunneling to communicate with C2.

T1082
System Information Discovery
MalwareAnchor

Anchor can determine the hostname and linux version on a compromised host.

T1095
Non-Application Layer Protocol
MalwareAnchor

Anchor has used ICMP in C2 communications.

T1105
Ingress Tool Transfer
MalwareAnchor

Anchor can download additional payloads.

T1480
Execution Guardrails
MalwareAnchor

Anchor can terminate itself if specific execution flags are not present.

T1543.003
Windows Service
MalwareAnchor

Anchor can establish persistence by creating a service.

T1553.002
Code Signing
MalwareAnchor

Anchor has been signed with valid certificates to evade detection by security tools.

T1564.004
NTFS File Attributes
MalwareAnchor

Anchor has used NTFS to hide files.

T1569.002
Service Execution
MalwareAnchor

Anchor can create and execute services to load its payload.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.