ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1022×

19 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareIceApple

IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`.

T1003.004
LSA Secrets
MalwareIceApple

IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`.

T1005
Data from Local System
MalwareIceApple

IceApple can collect files, passwords, and other data from a compromised host.

T1016
System Network Configuration Discovery
MalwareIceApple

The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks.

T1027.010
Command Obfuscation
MalwareIceApple

IceApple can use Base64 and "junk" JavaScript code to obfuscate information.

T1036.005
Match Legitimate Resource Name or Location
MalwareIceApple

IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate.

T1041
Exfiltration Over C2 Channel
MalwareIceApple

IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2.

T1056.003
Web Portal Capture
MalwareIceApple

The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials.

T1070.004
File Deletion
MalwareIceApple

IceApple can delete files and directories from targeted systems.

T1071.001
Web Protocols
MalwareIceApple

IceApple can use HTTP GET to request and pull information from C2.

T1082
System Information Discovery
MalwareIceApple

The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary.

T1083
File and Directory Discovery
MalwareIceApple

The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size.

T1087.002
Domain Account
MalwareIceApple

The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server.

T1140
Deobfuscate/Decode Files or Information
MalwareIceApple

IceApple can use a Base64-encoded AES key to decrypt tasking.

T1505.004
IIS Components
MalwareIceApple

IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities.

T1552.002
Credentials in Registry
MalwareIceApple

IceApple can harvest credentials from local and remote host registries.

T1560.001
Archive via Utility
MalwareIceApple

IceApple can encrypt and compress files using Gzip prior to exfiltration.

T1573.001
Symmetric Cryptography
MalwareIceApple

The IceApple Result Retriever module can AES encrypt C2 responses.

T1620
Reflective Code Loading
MalwareIceApple

IceApple can use reflective code loading to load .NET assemblies into `MSExchangeOWAAppPool` on targeted Exchange servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.