Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAvaddon | Avaddon can collect the external IP address of the victim. |
| T1027 Obfuscated Files or Information |
MalwareAvaddon | Avaddon has used encrypted strings. |
| T1047 Windows Management Instrumentation |
MalwareAvaddon | Avaddon uses wmic.exe to delete shadow copies. |
| T1057 Process Discovery |
MalwareAvaddon | Avaddon has collected information about running processes. |
| T1059.007 JavaScript |
MalwareAvaddon | Avaddon has been executed through a malicious JScript downloader. |
| T1083 File and Directory Discovery |
MalwareAvaddon | Avaddon has searched for specific files prior to encryption. |
| T1106 Native API |
MalwareAvaddon | Avaddon has used the Windows Crypto API to generate an AES key. |
| T1112 Modify Registry |
MalwareAvaddon | Avaddon modifies several registry keys for persistence and UAC bypass. |
| T1135 Network Share Discovery |
MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvaddon | Avaddon has decrypted encrypted strings. |
| T1486 Data Encrypted for Impact |
MalwareAvaddon | Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes. |
| T1489 Service Stop |
MalwareAvaddon | Avaddon looks for and attempts to stop database processes. |
| T1490 Inhibit System Recovery |
MalwareAvaddon | Avaddon deletes backups and shadow copies using native system tools. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvaddon | Avaddon uses registry run keys for persistence. |
| T1548.002 Bypass User Account Control |
MalwareAvaddon | Avaddon bypasses UAC using the CMSTPLUA COM interface. |
| T1614.001 System Language Discovery |
MalwareAvaddon | Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities. |
| T1685 Disable or Modify Tools |
MalwareAvaddon | Avaddon looks for and attempts to stop anti-malware solutions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.