Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareGreen Lambert | Green Lambert can collect data from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareGreen Lambert | Green Lambert can obtain proxy information from a victim's machine using system environment variables. |
| T1027 Obfuscated Files or Information |
MalwareGreen Lambert | Green Lambert has encrypted strings. |
| T1036.004 Masquerade Task or Service |
MalwareGreen Lambert | Green Lambert has created a new executable named `Software Update Check` to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGreen Lambert | Green Lambert has been disguised as a Growl help file. |
| T1037.004 RC Scripts |
MalwareGreen Lambert | Green Lambert can add |
| T1059.004 Unix Shell |
MalwareGreen Lambert | Green Lambert can use shell scripts for execution, such as |
| T1070.004 File Deletion |
MalwareGreen Lambert | Green Lambert can delete the original executable after initial installation in addition to unused functions. |
| T1071.004 DNS |
MalwareGreen Lambert | Green Lambert can use DNS for C2 communications. |
| T1082 System Information Discovery |
MalwareGreen Lambert | Green Lambert can use `uname` to identify the operating system name, version, and processor type. |
| T1090 Proxy |
MalwareGreen Lambert | Green Lambert can use proxies for C2 traffic. |
| T1124 System Time Discovery |
MalwareGreen Lambert | Green Lambert can collect the date and time from a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGreen Lambert | Green Lambert can use multiple custom routines to decrypt strings prior to execution. |
| T1543.001 Launch Agent |
MalwareGreen Lambert | Green Lambert can create a Launch Agent with the `RunAtLoad` key-value pair set to |
| T1543.004 Launch Daemon |
MalwareGreen Lambert | Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence. |
| T1546.004 Unix Shell Configuration Modification |
MalwareGreen Lambert | Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells. |
| T1547.015 Login Items |
MalwareGreen Lambert | Green Lambert can add Login Items to establish persistence. |
| T1555.001 Keychain |
MalwareGreen Lambert | Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.