Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.015 Compression |
MalwareRCSession | RCSession can compress and obfuscate its strings to evade detection on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareRCSession | RCSession can gather system owner information, including user and administrator privileges. |
| T1036 Masquerading |
MalwareRCSession | RCSession has used a file named English.rtf to appear benign on victim hosts. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareRCSession | RCSession can identify processes based on PID. |
| T1059.003 Windows Command Shell |
MalwareRCSession | RCSession can use `cmd.exe` for execution on compromised hosts. |
| T1070.004 File Deletion |
MalwareRCSession | RCSession can remove files from a targeted system. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareRCSession | RCSession can gather system information from a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareRCSession | RCSession has the ability to drop additional files to an infected machine. |
| T1106 Native API |
MalwareRCSession | RCSession can use WinSock API for communication including |
| T1112 Modify Registry |
MalwareRCSession | RCSession can write its configuration file to the Registry. |
| T1113 Screen Capture |
MalwareRCSession | RCSession can capture screenshots from a compromised host. |
| T1218.007 Msiexec |
MalwareRCSession | RCSession has the ability to execute inside the msiexec.exe process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareRCSession | RCSession can bypass UAC to escalate privileges. |
| T1573 Encrypted Channel |
MalwareRCSession | RCSession can use an encrypted beacon to check in with C2. |
| T1574.001 DLL |
MalwareRCSession | RCSession can be installed via DLL side-loading. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.