Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
ToolPcShare | PcShare can collect files and information from a compromised host. |
| T1012 Query Registry |
ToolPcShare | PcShare can search the registry files of a compromised host. |
| T1016 System Network Configuration Discovery |
ToolPcShare | PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`. |
| T1027.013 Encrypted/Encoded File |
ToolPcShare | PcShare has been encrypted with XOR using different 32-long Base16 strings. |
| T1027.015 Compression |
ToolPcShare | PcShare has been compressed with LZW algorithm. |
| T1036.001 Invalid Code Signature |
ToolPcShare | PcShare has used an invalid certificate in attempt to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolPcShare | PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client. |
| T1041 Exfiltration Over C2 Channel |
ToolPcShare | PcShare can upload files and information from a compromised host to its C2 servers. |
| T1055 Process Injection |
ToolPcShare | The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes. |
| T1056.001 Keylogging |
ToolPcShare | PcShare has the ability to capture keystrokes. |
| T1057 Process Discovery |
ToolPcShare | PcShare can obtain a list of running processes on a compromised host. |
| T1059.003 Windows Command Shell |
ToolPcShare | PcShare can execute `cmd` commands on a compromised host. |
| T1070.004 File Deletion |
ToolPcShare | PcShare has deleted its files and components from a compromised host. |
| T1071.001 Web Protocols |
ToolPcShare | PcShare has used HTTP for C2 communication. |
| T1106 Native API |
ToolPcShare | PcShare has used a variety of Windows API functions. |
| T1112 Modify Registry |
ToolPcShare | PcShare can delete its persistence mechanisms from the registry. |
| T1113 Screen Capture |
ToolPcShare | PcShare can take screen shots of a compromised machine. |
| T1125 Video Capture |
ToolPcShare | PcShare can capture camera video as part of its collection process. |
| T1140 Deobfuscate/Decode Files or Information |
ToolPcShare | PcShare has decrypted its strings by applying a XOR operation and a decompression using a custom implemented LZM algorithm. |
| T1218.011 Rundll32 |
ToolPcShare | PcShare has used `rundll32.exe` for execution. |
| T1546.015 Component Object Model Hijacking |
ToolPcShare | PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.