Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareAnchor | Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1016 System Network Configuration Discovery |
MalwareAnchor | Anchor can determine the public IP and location of a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
MalwareAnchor | Anchor can support windows execution via SMB shares. |
| T1027 Obfuscated Files or Information |
MalwareAnchor | Anchor has obfuscated code with stack strings and string encryption. |
| T1027.002 Software Packing |
MalwareAnchor | Anchor has come with a packed payload. |
| T1053.003 Cron |
MalwareAnchor | Anchor can install itself as a cron job. |
| T1053.005 Scheduled Task |
MalwareAnchor | Anchor can create a scheduled task for persistence. |
| T1059.003 Windows Command Shell |
MalwareAnchor | Anchor has used cmd.exe to run its self deletion routine. |
| T1059.004 Unix Shell |
MalwareAnchor | Anchor can execute payloads via shell scripting. |
| T1070.004 File Deletion |
MalwareAnchor | Anchor can self delete its dropper after the malware is successfully deployed. |
| T1071.001 Web Protocols |
MalwareAnchor | Anchor has used HTTP and HTTPS in C2 communications. |
| T1071.004 DNS |
MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1082 System Information Discovery |
MalwareAnchor | Anchor can determine the hostname and linux version on a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareAnchor | Anchor has used ICMP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareAnchor | Anchor can download additional payloads. |
| T1480 Execution Guardrails |
MalwareAnchor | Anchor can terminate itself if specific execution flags are not present. |
| T1543.003 Windows Service |
MalwareAnchor | Anchor can establish persistence by creating a service. |
| T1553.002 Code Signing |
MalwareAnchor | Anchor has been signed with valid certificates to evade detection by security tools. |
| T1564.004 NTFS File Attributes |
MalwareAnchor | Anchor has used NTFS to hide files. |
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.