ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0583×

16 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwarePysa

Pysa can perform OS credential dumping using Mimikatz.

T1016
System Network Configuration Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced IP Scanner tool.

T1021.001
Remote Desktop Protocol
MalwarePysa

Pysa has laterally moved using RDP connections.

T1036.005
Match Legitimate Resource Name or Location
MalwarePysa

Pysa has executed a malicious executable by naming it svchost.exe.

T1046
Network Service Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced Port Scanner tool.

T1059.001
PowerShell
MalwarePysa

Pysa has used Powershell scripts to deploy its ransomware.

T1059.006
Python
MalwarePysa

Pysa has used Python scripts to deploy ransomware.

T1070.004
File Deletion
MalwarePysa

Pysa has deleted batch files after execution.

T1110
Brute Force
MalwarePysa

Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.

T1112
Modify Registry
MalwarePysa

Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.

T1486
Data Encrypted for Impact
MalwarePysa

Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.

T1489
Service Stop
MalwarePysa

Pysa can stop services and processes.

T1490
Inhibit System Recovery
MalwarePysa

Pysa has the functionality to delete shadow copies.

T1552.001
Credentials In Files
MalwarePysa

Pysa has extracted credentials from the password database before encrypting the files.

T1569.002
Service Execution
MalwarePysa

Pysa has used PsExec to copy and execute the ransomware.

T1685
Disable or Modify Tools
MalwarePysa

Pysa has the capability to stop antivirus services and disable Windows Defender.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.