Real-world descriptions of how a group, tool or campaign used a technique.
27 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64(). |
| T1027.002 Software Packing |
MalwareHildegard | Hildegard has packed ELF files into other binaries. |
| T1027.013 Encrypted/Encoded File |
MalwareHildegard | Hildegard has encrypted an ELF file. |
| T1036.004 Masquerade Task or Service |
MalwareHildegard | Hildegard has disguised itself as a known Linux process. |
| T1046 Network Service Discovery |
MalwareHildegard | Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1059.004 Unix Shell |
MalwareHildegard | Hildegard has used shell scripts for execution. |
| T1068 Exploitation for Privilege Escalation |
MalwareHildegard | Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1070.003 Clear Command History |
MalwareHildegard | Hildegard has used history -c to clear script shell logs. |
| T1070.004 File Deletion |
MalwareHildegard | Hildegard has deleted scripts after execution. |
| T1071 Application Layer Protocol |
MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| T1082 System Information Discovery |
MalwareHildegard | Hildegard has collected the host's OS, CPU, and memory information. |
| T1102 Web Service |
MalwareHildegard | Hildegard has downloaded scripts from GitHub. |
| T1105 Ingress Tool Transfer |
MalwareHildegard | Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners. |
| T1133 External Remote Services |
MalwareHildegard | Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment. |
| T1136.001 Local Account |
MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHildegard | Hildegard has decrypted ELF files with AES. |
| T1219 Remote Access Tools |
MalwareHildegard | Hildegard has established tmate sessions for C2 communications. |
| T1496.001 Compute Hijacking |
MalwareHildegard | Hildegard has used xmrig to mine cryptocurrency. |
| T1543.002 Systemd Service |
MalwareHildegard | Hildegard has started a monero service. |
| T1552.001 Credentials In Files |
MalwareHildegard | Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens. |
| T1552.004 Private Keys |
MalwareHildegard | Hildegard has searched for private keys in .ssh. |
| T1552.005 Cloud Instance Metadata API |
MalwareHildegard | Hildegard has queried the Cloud Instance Metadata API for cloud credentials. |
| T1574.006 Dynamic Linker Hijacking |
MalwareHildegard | Hildegard has modified /etc/ld.so.preload to intercept shared library import functions. |
| T1609 Container Administration Command |
MalwareHildegard | Hildegard was executed through the kubelet API run command and by executing commands on running containers. |
| T1611 Escape to Host |
MalwareHildegard | Hildegard has used the BOtB tool that can break out of containers. |
| T1613 Container and Resource Discovery |
MalwareHildegard | Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers. |
| T1685 Disable or Modify Tools |
MalwareHildegard | Hildegard has modified DNS resolvers to evade DNS monitoring tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.