ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0662×

22 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1027.011
Fileless Storage
MalwareRCSession

RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`.

T1027.015
Compression
MalwareRCSession

RCSession can compress and obfuscate its strings to evade detection on a compromised host.

T1033
System Owner/User Discovery
MalwareRCSession

RCSession can gather system owner information, including user and administrator privileges.

T1036
Masquerading
MalwareRCSession

RCSession has used a file named English.rtf to appear benign on victim hosts.

T1055.012
Process Hollowing
MalwareRCSession

RCSession can launch itself from a hollowed svchost.exe process.

T1056.001
Keylogging
MalwareRCSession

RCSession has the ability to capture keystrokes on a compromised host.

T1057
Process Discovery
MalwareRCSession

RCSession can identify processes based on PID.

T1059.003
Windows Command Shell
MalwareRCSession

RCSession can use `cmd.exe` for execution on compromised hosts.

T1070.004
File Deletion
MalwareRCSession

RCSession can remove files from a targeted system.

T1071.001
Web Protocols
MalwareRCSession

RCSession can use HTTP in C2 communications.

T1082
System Information Discovery
MalwareRCSession

RCSession can gather system information from a compromised host.

T1095
Non-Application Layer Protocol
MalwareRCSession

RCSession has the ability to use TCP and UDP in C2 communications.

T1105
Ingress Tool Transfer
MalwareRCSession

RCSession has the ability to drop additional files to an infected machine.

T1106
Native API
MalwareRCSession

RCSession can use WinSock API for communication including WSASend and WSARecv.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1113
Screen Capture
MalwareRCSession

RCSession can capture screenshots from a compromised host.

T1218.007
Msiexec
MalwareRCSession

RCSession has the ability to execute inside the msiexec.exe process.

T1547.001
Registry Run Keys / Startup Folder
MalwareRCSession

RCSession has the ability to modify a Registry Run key to establish persistence.

T1548.002
Bypass User Account Control
MalwareRCSession

RCSession can bypass UAC to escalate privileges.

T1573
Encrypted Channel
MalwareRCSession

RCSession can use an encrypted beacon to check in with C2.

T1574.001
DLL
MalwareRCSession

RCSession can be installed via DLL side-loading.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.