ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0663×

31 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSysUpdate

SysUpdate can collect information and files from a compromised host.

T1007
System Service Discovery
MalwareSysUpdate

SysUpdate can collect a list of services on a victim machine.

T1016
System Network Configuration Discovery
MalwareSysUpdate

SysUpdate can collected the IP address and domain name of a compromised host.

T1016.001
Internet Connection Discovery
MalwareSysUpdate

SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process.

T1027.002
Software Packing
MalwareSysUpdate

SysUpdate has been packed with VMProtect.

T1027.011
Fileless Storage
MalwareSysUpdate

SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1027.013
Encrypted/Encoded File
MalwareSysUpdate

SysUpdate can encrypt and encode its configuration file.

T1033
System Owner/User Discovery
MalwareSysUpdate

SysUpdate can collect the username from a compromised host.

T1036.004
Masquerade Task or Service
MalwareSysUpdate

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1041
Exfiltration Over C2 Channel
MalwareSysUpdate

SysUpdate has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation
MalwareSysUpdate

SysUpdate can use WMI for execution on a compromised host.

T1057
Process Discovery
MalwareSysUpdate

SysUpdate can collect information about running processes.

T1070.004
File Deletion
MalwareSysUpdate

SysUpdate can delete its configuration file from the targeted system.

T1071.004
DNS
MalwareSysUpdate

SysUpdate has used DNS TXT requests as for its C2 communication.

T1082
System Information Discovery
MalwareSysUpdate

SysUpdate can collect a system's architecture, operating system version, and hostname.

T1083
File and Directory Discovery
MalwareSysUpdate

SysUpdate can search files on a compromised host.

T1105
Ingress Tool Transfer
MalwareSysUpdate

SysUpdate has the ability to download files to a compromised host.

T1106
Native API
MalwareSysUpdate

SysUpdate can call the `GetNetworkParams` API as part of its C2 establishment process.

T1112
Modify Registry
MalwareSysUpdate

SysUpdate can write its configuration file to Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1113
Screen Capture
MalwareSysUpdate

SysUpdate has the ability to capture screenshots.

T1132.001
Standard Encoding
MalwareSysUpdate

SysUpdate has used Base64 to encode its C2 traffic.

T1140
Deobfuscate/Decode Files or Information
MalwareSysUpdate

SysUpdate can deobfuscate packed binaries in memory.

T1543.002
Systemd Service
MalwareSysUpdate

SysUpdate can copy a script to the user owned `/usr/lib/systemd/system/` directory with a symlink mapped to a `root` owned directory, `/etc/ystem/system`, in the unit configuration file's `ExecStart` directive to establish persistence and elevate privileges.

T1543.003
Windows Service
MalwareSysUpdate

SysUpdate can create a service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSysUpdate

SysUpdate can use a Registry Run key to establish persistence.

T1553.002
Code Signing
MalwareSysUpdate

SysUpdate has been signed with stolen digital certificates.

T1564.001
Hidden Files and Directories
MalwareSysUpdate

SysUpdate has the ability to set file attributes to hidden.

T1569.002
Service Execution
MalwareSysUpdate

SysUpdate can manage services and processes.

T1573.001
Symmetric Cryptography
MalwareSysUpdate

SysUpdate has used DES to encrypt all C2 communications.

T1574.001
DLL
MalwareSysUpdate

SysUpdate can load DLLs through vulnerable legitimate executables.

T1680
Local Storage Discovery
MalwareSysUpdate

SysUpdate can collect a system's drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.