ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0601×

27 examples

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1027.002
Software Packing
MalwareHildegard

Hildegard has packed ELF files into other binaries.

T1027.013
Encrypted/Encoded File
MalwareHildegard

Hildegard has encrypted an ELF file.

T1036.004
Masquerade Task or Service
MalwareHildegard

Hildegard has disguised itself as a known Linux process.

T1046
Network Service Discovery
MalwareHildegard

Hildegard has used masscan to look for kubelets in the internal Kubernetes network.

T1059.004
Unix Shell
MalwareHildegard

Hildegard has used shell scripts for execution.

T1068
Exploitation for Privilege Escalation
MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1070.003
Clear Command History
MalwareHildegard

Hildegard has used history -c to clear script shell logs.

T1070.004
File Deletion
MalwareHildegard

Hildegard has deleted scripts after execution.

T1071
Application Layer Protocol
MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

T1082
System Information Discovery
MalwareHildegard

Hildegard has collected the host's OS, CPU, and memory information.

T1102
Web Service
MalwareHildegard

Hildegard has downloaded scripts from GitHub.

T1105
Ingress Tool Transfer
MalwareHildegard

Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners.

T1133
External Remote Services
MalwareHildegard

Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment.

T1136.001
Local Account
MalwareHildegard

Hildegard has created a user named “monerodaemon”.

T1140
Deobfuscate/Decode Files or Information
MalwareHildegard

Hildegard has decrypted ELF files with AES.

T1219
Remote Access Tools
MalwareHildegard

Hildegard has established tmate sessions for C2 communications.

T1496.001
Compute Hijacking
MalwareHildegard

Hildegard has used xmrig to mine cryptocurrency.

T1543.002
Systemd Service
MalwareHildegard

Hildegard has started a monero service.

T1552.001
Credentials In Files
MalwareHildegard

Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens.

T1552.004
Private Keys
MalwareHildegard

Hildegard has searched for private keys in .ssh.

T1552.005
Cloud Instance Metadata API
MalwareHildegard

Hildegard has queried the Cloud Instance Metadata API for cloud credentials.

T1574.006
Dynamic Linker Hijacking
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to intercept shared library import functions.

T1609
Container Administration Command
MalwareHildegard

Hildegard was executed through the kubelet API run command and by executing commands on running containers.

T1611
Escape to Host
MalwareHildegard

Hildegard has used the BOtB tool that can break out of containers.

T1613
Container and Resource Discovery
MalwareHildegard

Hildegard has used masscan to search for kubelets and the kubelet API for additional running containers.

T1685
Disable or Modify Tools
MalwareHildegard

Hildegard has modified DNS resolvers to evade DNS monitoring tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.