Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMilan | Milan can upload files from a compromised host. |
| T1012 Query Registry |
MalwareMilan | Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1016 System Network Configuration Discovery |
MalwareMilan | Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings. |
| T1027.013 Encrypted/Encoded File |
MalwareMilan | Milan can encode files containing information about the targeted system. |
| T1033 System Owner/User Discovery |
MalwareMilan | Milan can identify users registered to a targeted machine. |
| T1036 Masquerading |
MalwareMilan | Milan has used an executable named `companycatalogue` to appear benign. |
| T1036.007 Double File Extension |
MalwareMilan | Milan has used an executable named `companycatalog.exe.config` to appear benign. |
| T1053.005 Scheduled Task |
MalwareMilan | Milan can establish persistence on a targeted host with scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareMilan | Milan can use `cmd.exe` for discovery actions on a targeted system. |
| T1070.004 File Deletion |
MalwareMilan | Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1074.001 Local Data Staging |
MalwareMilan | Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`. |
| T1082 System Information Discovery |
MalwareMilan | Milan can enumerate the targeted machine's name and GUID. |
| T1087.001 Local Account |
MalwareMilan | Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts. |
| T1105 Ingress Tool Transfer |
MalwareMilan | Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`. |
| T1106 Native API |
MalwareMilan | Milan can use the API `DnsQuery_A` for DNS resolution. |
| T1559.001 Component Object Model |
MalwareMilan | Milan can use a COM component to generate scheduled tasks. |
| T1568.002 Domain Generation Algorithms |
MalwareMilan | Milan can use hardcoded domains as an input for domain generation algorithms. |
| T1572 Protocol Tunneling |
MalwareMilan | Milan can use a custom protocol tunneled through DNS or HTTP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.