ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1020×

21 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareKevin

Kevin can generate a sequence of dummy HTTP C2 requests to obscure traffic.

T1005
Data from Local System
MalwareKevin

Kevin can upload logs and other data from a compromised host.

T1008
Fallback Channels
MalwareKevin

Kevin can assign hard-coded fallback domains for C2.

T1016
System Network Configuration Discovery
MalwareKevin

Kevin can collect the MAC address and other information from a victim machine using `ipconfig/all`.

T1027.013
Encrypted/Encoded File
MalwareKevin

Kevin has Base64-encoded its configuration file.

T1030
Data Transfer Size Limits
MalwareKevin

Kevin can exfiltrate data to the C2 server in 27-character chunks.

T1036.003
Rename Legitimate Utilities
MalwareKevin

Kevin has renamed an image of `cmd.exe` with a random name followed by a `.tmpl` extension.

T1041
Exfiltration Over C2 Channel
MalwareKevin

Kevin can send data from the victim host through a DNS C2 channel.

T1059.003
Windows Command Shell
MalwareKevin

Kevin can use a renamed image of `cmd.exe` for execution.

T1070.004
File Deletion
MalwareKevin

Kevin can delete files created on the victim's machine.

T1071.001
Web Protocols
MalwareKevin

Variants of Kevin can communicate with C2 over HTTP.

T1071.004
DNS
MalwareKevin

Variants of Kevin can communicate over DNS through queries to the server for constructed domain names with embedded information.

T1074
Data Staged
MalwareKevin

Kevin can create directories to store logs and other collected data.

T1082
System Information Discovery
MalwareKevin

Kevin can enumerate the OS version and hostname of a targeted machine.

T1105
Ingress Tool Transfer
MalwareKevin

Kevin can download files to the compromised host.

T1106
Native API
MalwareKevin

Kevin can use the `ShowWindow` API to avoid detection.

T1132.001
Standard Encoding
MalwareKevin

Kevin can Base32 encode chunks of output files during exfiltration.

T1497
Virtualization/Sandbox Evasion
MalwareKevin

Kevin can sleep for a time interval between C2 communication attempts.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareKevin

Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware.

T1564.003
Hidden Window
MalwareKevin

Kevin can hide the current window from the targeted user via the `ShowWindow` API function.

T1572
Protocol Tunneling
MalwareKevin

Kevin can use a custom protocol tunneled through DNS or HTTP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.