Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareKGH_SPY | KGH_SPY can send a file containing victim system information to C2. |
| T1027.013 Encrypted/Encoded File |
MalwareKGH_SPY | KGH_SPY has used encrypted strings in its installer. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKGH_SPY | KGH_SPY has masqueraded as a legitimate Windows tool. |
| T1037.001 Logon Script (Windows) |
MalwareKGH_SPY | KGH_SPY has the ability to set the |
| T1041 Exfiltration Over C2 Channel |
MalwareKGH_SPY | KGH_SPY can exfiltrate collected information from the host to the C2 server. |
| T1056.001 Keylogging |
MalwareKGH_SPY | KGH_SPY can perform keylogging by polling the |
| T1059.001 PowerShell |
MalwareKGH_SPY | KGH_SPY can execute PowerShell commands on the victim's machine. |
| T1059.003 Windows Command Shell |
MalwareKGH_SPY | KGH_SPY has the ability to set a Registry key to run a cmd.exe command. |
| T1071.001 Web Protocols |
MalwareKGH_SPY | KGH_SPY can send data to C2 with HTTP POST requests. |
| T1074.001 Local Data Staging |
MalwareKGH_SPY | KGH_SPY can save collected system information to a file named "info" before exfiltration. |
| T1083 File and Directory Discovery |
MalwareKGH_SPY | KGH_SPY can enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareKGH_SPY | KGH_SPY has the ability to download and execute code from remote servers. |
| T1114.001 Local Email Collection |
MalwareKGH_SPY | KGH_SPY can harvest data from mail clients. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKGH_SPY | KGH_SPY can decrypt encrypted strings and write them to a newly created folder. |
| T1204.002 Malicious File |
MalwareKGH_SPY | KGH_SPY has been spread through Word documents containing malicious macros. |
| T1518 Software Discovery |
MalwareKGH_SPY | KGH_SPY can collect information on installed applications. |
| T1555 Credentials from Password Stores |
MalwareKGH_SPY | KGH_SPY can collect credentials from WINSCP. |
| T1555.003 Credentials from Web Browsers |
MalwareKGH_SPY | KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers. |
| T1555.004 Windows Credential Manager |
MalwareKGH_SPY | KGH_SPY can collect credentials from the Windows Credential Manager. |
| T1680 Local Storage Discovery |
MalwareKGH_SPY | KGH_SPY can collect drive information from a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.