Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareShark | Shark can upload files to its C2. |
| T1008 Fallback Channels |
MalwareShark | Shark can update its configuration to use a different C2 server. |
| T1012 Query Registry |
MalwareShark | Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1027.013 Encrypted/Encoded File |
MalwareShark | Shark can use encrypted and encoded files for C2 configuration. |
| T1029 Scheduled Transfer |
MalwareShark | Shark can pause C2 communications for a specified time. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShark | Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
MalwareShark | Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel. |
| T1059.003 Windows Command Shell |
MalwareShark | Shark has the ability to use `CMD` to execute commands. |
| T1070.004 File Deletion |
MalwareShark | Shark can delete files downloaded to the compromised host. |
| T1071.001 Web Protocols |
MalwareShark | Shark has the ability to use HTTP in C2 communications. |
| T1071.004 DNS |
MalwareShark | Shark can use DNS in C2 communications. |
| T1074 Data Staged |
MalwareShark | Shark has stored information in folders named `U1` and `U2` prior to exfiltration. |
| T1082 System Information Discovery |
MalwareShark | Shark can collect the GUID of a targeted machine. |
| T1105 Ingress Tool Transfer |
MalwareShark | Shark can download additional files from its C2 via HTTP or DNS. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShark | Shark can extract and decrypt downloaded .zip files. |
| T1497.001 System Checks |
MalwareShark | Shark can stop execution if the screen width of the targeted machine is not over 600 pixels. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.