ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0633×

23 examples

TechniqueUsed byProcedure example
T1001.002
Steganography
ToolSliver

Sliver can encode binary data into a .PNG file for C2 communication.

T1003.001
LSASS Memory
ToolSliver

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1016
System Network Configuration Discovery
ToolSliver

Sliver has the ability to gather network configuration information.

T1027
Obfuscated Files or Information
ToolSliver

Sliver obfuscates configuration and other static files using native Go libraries such as `garble` and `gobfuscate` to inhibit configuration analysis and static detection.

T1027.004
Compile After Delivery
ToolSliver

Sliver includes functionality to retrieve source code and compile locally prior to execution in victim environments.

T1027.013
Encrypted/Encoded File
ToolSliver

Sliver can encrypt strings at compile time.

T1041
Exfiltration Over C2 Channel
ToolSliver

Sliver can exfiltrate files from the victim using the download command.

T1049
System Network Connections Discovery
ToolSliver

Sliver can collect network connection information.

T1055
Process Injection
ToolSliver

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1059.001
PowerShell
ToolSliver

Sliver has built-in functionality to launch a Powershell command prompt.

T1071
Application Layer Protocol
ToolSliver

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071.001
Web Protocols
ToolSliver

Sliver has the ability to support C2 communications over HTTP and HTTPS.

T1071.004
DNS
ToolSliver

Sliver can support C2 communications over DNS.

T1083
File and Directory Discovery
ToolSliver

Sliver can enumerate files on a target system.

T1090.001
Internal Proxy
ToolSliver

Sliver has a built-in SOCKS5 proxying capability allowing for Sliver clients to proxy network traffic through other clients within a victim network.

T1105
Ingress Tool Transfer
ToolSliver

Sliver can download additional content and files from the Sliver server to the client residing on the victim machine using the upload command.

T1113
Screen Capture
ToolSliver

Sliver can take screenshots of the victim’s active display.

T1132.001
Standard Encoding
ToolSliver

Sliver can use standard encoding techniques like gzip and hex to ASCII to encode the C2 communication payload.

T1134
Access Token Manipulation
ToolSliver

Sliver has the ability to manipulate user tokens on targeted Windows systems.

T1548.002
Bypass User Account Control
ToolSliver

Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems.

T1558.001
Golden Ticket
ToolSliver

Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets.

T1573.001
Symmetric Cryptography
ToolSliver

Sliver can use AES-GCM-256 to encrypt a session key for C2 message exchange.

T1573.002
Asymmetric Cryptography
ToolSliver

Sliver can use mutual TLS and RSA cryptography to exchange a session key.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.