ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1015×

20 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareMilan

Milan can upload files from a compromised host.

T1012
Query Registry
MalwareMilan

Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1016
System Network Configuration Discovery
MalwareMilan

Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings.

T1027.013
Encrypted/Encoded File
MalwareMilan

Milan can encode files containing information about the targeted system.

T1033
System Owner/User Discovery
MalwareMilan

Milan can identify users registered to a targeted machine.

T1036
Masquerading
MalwareMilan

Milan has used an executable named `companycatalogue` to appear benign.

T1036.007
Double File Extension
MalwareMilan

Milan has used an executable named `companycatalog.exe.config` to appear benign.

T1053.005
Scheduled Task
MalwareMilan

Milan can establish persistence on a targeted host with scheduled tasks.

T1059.003
Windows Command Shell
MalwareMilan

Milan can use `cmd.exe` for discovery actions on a targeted system.

T1070.004
File Deletion
MalwareMilan

Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`.

T1071.001
Web Protocols
MalwareMilan

Milan can use HTTPS for communication with C2.

T1071.004
DNS
MalwareMilan

Milan has the ability to use DNS for C2 communications.

T1074.001
Local Data Staging
MalwareMilan

Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`.

T1082
System Information Discovery
MalwareMilan

Milan can enumerate the targeted machine's name and GUID.

T1087.001
Local Account
MalwareMilan

Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts.

T1105
Ingress Tool Transfer
MalwareMilan

Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`.

T1106
Native API
MalwareMilan

Milan can use the API `DnsQuery_A` for DNS resolution.

T1559.001
Component Object Model
MalwareMilan

Milan can use a COM component to generate scheduled tasks.

T1568.002
Domain Generation Algorithms
MalwareMilan

Milan can use hardcoded domains as an input for domain generation algorithms.

T1572
Protocol Tunneling
MalwareMilan

Milan can use a custom protocol tunneled through DNS or HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.