Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareGrimAgent | GrimAgent can pad C2 messages with random generated values. |
| T1005 Data from Local System |
MalwareGrimAgent | GrimAgent can collect data and files from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareGrimAgent | GrimAgent can enumerate the IP and domain of a target system. |
| T1027 Obfuscated Files or Information |
MalwareGrimAgent | GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings. |
| T1027.001 Binary Padding |
MalwareGrimAgent | GrimAgent has the ability to add bytes to change the file hash. |
| T1033 System Owner/User Discovery |
MalwareGrimAgent | GrimAgent can identify the user id on a target machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareGrimAgent | GrimAgent has sent data related to a compromise host over its C2 channel. |
| T1053.005 Scheduled Task |
MalwareGrimAgent | GrimAgent has the ability to set persistence using the Task Scheduler. |
| T1059.003 Windows Command Shell |
MalwareGrimAgent | GrimAgent can use the Windows Command Shell to execute commands, including its own removal. |
| T1070.004 File Deletion |
MalwareGrimAgent | GrimAgent can delete old binaries on a compromised host. |
| T1070.009 Clear Persistence |
MalwareGrimAgent | GrimAgent can delete previously created tasks on a compromised host. |
| T1071.001 Web Protocols |
MalwareGrimAgent | GrimAgent has the ability to use HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareGrimAgent | GrimAgent can collect the OS, and build version on a compromised host. |
| T1083 File and Directory Discovery |
MalwareGrimAgent | GrimAgent has the ability to enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareGrimAgent | GrimAgent has the ability to download and execute additional payloads. |
| T1106 Native API |
MalwareGrimAgent | GrimAgent can use Native API including |
| T1132.001 Standard Encoding |
MalwareGrimAgent | GrimAgent can base64 encode C2 replies. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGrimAgent | GrimAgent can use a decryption algorithm for strings based on Rotate on Right (RoR) and Rotate on Left (RoL) functionality. |
| T1480.002 Mutual Exclusion |
MalwareGrimAgent | GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`. |
| T1497.003 Time Based Checks |
MalwareGrimAgent | GrimAgent can sleep for 195 - 205 seconds after payload execution and before deleting its task. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrimAgent | GrimAgent can set persistence with a Registry run key. |
| T1573.001 Symmetric Cryptography |
MalwareGrimAgent | GrimAgent can use an AES key to encrypt C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareGrimAgent | GrimAgent can use a hardcoded server public RSA key to encrypt the first request to C2. |
| T1614 System Location Discovery |
MalwareGrimAgent | GrimAgent can identify the country code on a compromised host. |
| T1614.001 System Language Discovery |
MalwareGrimAgent | GrimAgent has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.