Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
ToolSliver | Sliver can encode binary data into a .PNG file for C2 communication. |
| T1003.001 LSASS Memory |
ToolSliver | Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting. |
| T1016 System Network Configuration Discovery |
ToolSliver | Sliver has the ability to gather network configuration information. |
| T1027 Obfuscated Files or Information |
ToolSliver | Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection. |
| T1027.004 Compile After Delivery |
ToolSliver | Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments. |
| T1027.013 Encrypted/Encoded File |
ToolSliver | Sliver can encrypt strings at compile time. |
| T1041 Exfiltration Over C2 Channel |
ToolSliver | Sliver can exfiltrate files from the victim using the |
| T1049 System Network Connections Discovery |
ToolSliver | Sliver can collect network connection information. |
| T1055 Process Injection |
ToolSliver | Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine. |
| T1059.001 PowerShell |
ToolSliver | Sliver has built-in functionality to launch a Powershell command prompt. |
| T1071 Application Layer Protocol |
ToolSliver | Sliver can utilize the Wireguard VPN protocol for command and control. |
| T1071.001 Web Protocols |
ToolSliver | Sliver has the ability to support C2 communications over HTTP and HTTPS. |
| T1071.004 DNS |
ToolSliver | Sliver can support C2 communications over DNS. |
| T1083 File and Directory Discovery |
ToolSliver | Sliver can enumerate files on a target system. |
| T1090.001 Internal Proxy |
ToolSliver | Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network. |
| T1105 Ingress Tool Transfer |
ToolSliver | Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the |
| T1113 Screen Capture |
ToolSliver | Sliver can take screenshots of the victim’s active display. |
| T1132.001 Standard Encoding |
ToolSliver | Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload. |
| T1134 Access Token Manipulation |
ToolSliver | Sliver has the ability to manipulate user tokens on targeted Windows systems. |
| T1548.002 Bypass User Account Control |
ToolSliver | Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems. |
| T1558.001 Golden Ticket |
ToolSliver | Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets. |
| T1573.001 Symmetric Cryptography |
ToolSliver | Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange. |
| T1573.002 Asymmetric Cryptography |
ToolSliver | Sliver can use mutual TLS and RSA cryptography to exchange a session key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.