ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1050×

21 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolPcShare

PcShare can collect files and information from a compromised host.

T1012
Query Registry
ToolPcShare

PcShare can search the registry files of a compromised host.

T1016
System Network Configuration Discovery
ToolPcShare

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1027.013
Encrypted/Encoded File
ToolPcShare

PcShare has been encrypted with XOR using different 32-long Base16 strings.

T1027.015
Compression
ToolPcShare

PcShare has been compressed with LZW algorithm.

T1036.001
Invalid Code Signature
ToolPcShare

PcShare has used an invalid certificate in attempt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
ToolPcShare

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1041
Exfiltration Over C2 Channel
ToolPcShare

PcShare can upload files and information from a compromised host to its C2 servers.

T1055
Process Injection
ToolPcShare

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1056.001
Keylogging
ToolPcShare

PcShare has the ability to capture keystrokes.

T1057
Process Discovery
ToolPcShare

PcShare can obtain a list of running processes on a compromised host.

T1059.003
Windows Command Shell
ToolPcShare

PcShare can execute `cmd` commands on a compromised host.

T1070.004
File Deletion
ToolPcShare

PcShare has deleted its files and components from a compromised host.

T1071.001
Web Protocols
ToolPcShare

PcShare has used HTTP for C2 communication.

T1106
Native API
ToolPcShare

PcShare has used a variety of Windows API functions.

T1112
Modify Registry
ToolPcShare

PcShare can delete its persistence mechanisms from the registry.

T1113
Screen Capture
ToolPcShare

PcShare can take screen shots of a compromised machine.

T1125
Video Capture
ToolPcShare

PcShare can capture camera video as part of its collection process.

T1140
Deobfuscate/Decode Files or Information
ToolPcShare

PcShare has decrypted its strings by applying a XOR operation and a decompression using a custom implemented LZM algorithm.

T1218.011
Rundll32
ToolPcShare

PcShare has used `rundll32.exe` for execution.

T1546.015
Component Object Model Hijacking
ToolPcShare

PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.