Real-world descriptions of how a group, tool or campaign used a technique.
53 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolSILENTTRINITY | SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call. |
| T1007 System Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can search for modifiable services that could be used for privilege escalation. |
| T1010 Application Window Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`. |
| T1012 Query Registry |
ToolSILENTTRINITY | SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives. |
| T1018 Remote System Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate and collect the properties of domain computers. |
| T1021.003 Distributed Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM. |
| T1021.006 Windows Remote Management |
ToolSILENTTRINITY | SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM. |
| T1033 System Owner/User Discovery |
ToolSILENTTRINITY | SILENTTRINITY can gather a list of logged on users. |
| T1041 Exfiltration Over C2 Channel |
ToolSILENTTRINITY | SILENTTRINITY can transfer files from an infected host to the C2 server. |
| T1046 Network Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can scan for open ports on a compromised machine. |
| T1047 Windows Management Instrumentation |
ToolSILENTTRINITY | SILENTTRINITY can use WMI for lateral movement. |
| T1055 Process Injection |
ToolSILENTTRINITY | SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process. |
| T1056.001 Keylogging |
ToolSILENTTRINITY | SILENTTRINITY has a keylogging capability. |
| T1056.002 GUI Input Capture |
ToolSILENTTRINITY | SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials. |
| T1057 Process Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded. |
| T1059.001 PowerShell |
ToolSILENTTRINITY | SILENTTRINITY can use PowerShell to execute commands. |
| T1059.003 Windows Command Shell |
ToolSILENTTRINITY | SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM. |
| T1059.006 Python |
ToolSILENTTRINITY | SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems. |
| T1069.001 Local Groups |
ToolSILENTTRINITY | SILENTTRINITY can obtain a list of local groups and members. |
| T1069.002 Domain Groups |
ToolSILENTTRINITY | SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information. |
| T1070 Indicator Removal |
ToolSILENTTRINITY | SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys. |
| T1070.004 File Deletion |
ToolSILENTTRINITY | SILENTTRINITY can remove files from the compromised host. |
| T1082 System Information Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect information related to a compromised host, including OS version. |
| T1083 File and Directory Discovery |
ToolSILENTTRINITY | SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files. |
| T1087.002 Domain Account |
ToolSILENTTRINITY | SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information. |
| T1105 Ingress Tool Transfer |
ToolSILENTTRINITY | SILENTTRINITY can load additional files and tools, including Mimikatz. |
| T1106 Native API |
ToolSILENTTRINITY | SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`. |
| T1112 Modify Registry |
ToolSILENTTRINITY | SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP). |
| T1113 Screen Capture |
ToolSILENTTRINITY | SILENTTRINITY can take a screenshot of the current desktop. |
| T1115 Clipboard Data |
ToolSILENTTRINITY | SILENTTRINITY can monitor Clipboard text and can use `System.Windows.Forms.Clipboard.GetText()` to collect data from the clipboard. |
| T1124 System Time Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect start time information from a compromised host. |
| T1134.001 Token Impersonation/Theft |
ToolSILENTTRINITY | SILENTTRINITY can find a process owned by a specific user and impersonate the associated token. |
| T1134.003 Make and Impersonate Token |
ToolSILENTTRINITY | SILENTTRINITY can make tokens from known credentials. |
| T1135 Network Share Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate shares on a compromised host. |
| T1518.001 Security Software Discovery |
ToolSILENTTRINITY | SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID. |
| T1543.003 Windows Service |
ToolSILENTTRINITY | SILENTTRINITY can establish persistence by creating a new service. |
| T1546.001 Change Default File Association |
ToolSILENTTRINITY | SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process. |
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolSILENTTRINITY | SILENTTRINITY can create a WMI Event to execute a payload for persistence. |
| T1546.015 Component Object Model Hijacking |
ToolSILENTTRINITY | SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolSILENTTRINITY | SILENTTRINITY can establish a LNK file in the startup folder for persistence. |
| T1548.002 Bypass User Account Control |
ToolSILENTTRINITY | SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension. |
| T1552.006 Group Policy Preferences |
ToolSILENTTRINITY | SILENTTRINITY has a module that can extract cached GPP passwords. |
| T1555.003 Credentials from Web Browsers |
ToolSILENTTRINITY | SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge. |
| T1555.004 Windows Credential Manager |
ToolSILENTTRINITY | SILENTTRINITY can gather Windows Vault credentials. |
| T1556 Modify Authentication Process |
ToolSILENTTRINITY | SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook. |
| T1558.003 Kerberoasting |
ToolSILENTTRINITY | SILENTTRINITY contains a module to conduct Kerberoasting. |
| T1559.001 Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object. |
| T1564.003 Hidden Window |
ToolSILENTTRINITY | SILENTTRINITY has the ability to set its window state to hidden. |
| T1620 Reflective Code Loading |
ToolSILENTTRINITY | SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR. |
| T1680 Local Storage Discovery |
ToolSILENTTRINITY | SILENTTRINITY can collect information related to a compromised host, including a list of drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.