ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1017×

17 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOutSteel

OutSteel can collect information from a compromised host.

T1020
Automated Exfiltration
MalwareOutSteel

OutSteel can automatically upload collected files to its C2 server.

T1036.005
Match Legitimate Resource Name or Location
MalwareOutSteel

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1041
Exfiltration Over C2 Channel
MalwareOutSteel

OutSteel can upload files from a compromised host over its C2 channel.

T1057
Process Discovery
MalwareOutSteel

OutSteel can identify running processes on a compromised host.

T1059.003
Windows Command Shell
MalwareOutSteel

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.010
AutoHotKey & AutoIT
MalwareOutSteel

OutSteel was developed using the AutoIT scripting language.

T1070.004
File Deletion
MalwareOutSteel

OutSteel can delete itself following the successful execution of a follow-on payload.

T1071.001
Web Protocols
MalwareOutSteel

OutSteel has used HTTP for C2 communications.

T1083
File and Directory Discovery
MalwareOutSteel

OutSteel can search for specific file extensions, including zipped files.

T1105
Ingress Tool Transfer
MalwareOutSteel

OutSteel can download files from its C2 server.

T1119
Automated Collection
MalwareOutSteel

OutSteel can automatically scan for and collect files with specific extensions.

T1204.001
Malicious Link
MalwareOutSteel

OutSteel has relied on a user to click a malicious link within a spearphishing email.

T1204.002
Malicious File
MalwareOutSteel

OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.

T1566.001
Spearphishing Attachment
MalwareOutSteel

OutSteel has been distributed as a malicious attachment within a spearphishing email.

T1566.002
Spearphishing Link
MalwareOutSteel

OutSteel has been distributed through malicious links contained within spearphishing emails.

T1570
Lateral Tool Transfer
MalwareOutSteel

OutSteel can download the Saint Bot malware for follow-on execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.