Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareMafalda | Mafalda can dump password hashes from `LSASS.exe`. |
| T1005 Data from Local System |
MalwareMafalda | Mafalda can collect files and information from a compromised host. |
| T1012 Query Registry |
MalwareMafalda | Mafalda can enumerate Registry keys with all subkeys and values. |
| T1016 System Network Configuration Discovery |
MalwareMafalda | Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table. |
| T1027.013 Encrypted/Encoded File |
MalwareMafalda | Mafalda has been obfuscated and contains encrypted functions. |
| T1033 System Owner/User Discovery |
MalwareMafalda | Mafalda can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwareMafalda | Mafalda can send network system data and files to its C2 server. |
| T1049 System Network Connections Discovery |
MalwareMafalda | Mafalda can use the |
| T1056 Input Capture |
MalwareMafalda | Mafalda can conduct mouse event logging. |
| T1057 Process Discovery |
MalwareMafalda | Mafalda can enumerate running processes on a machine. |
| T1059.001 PowerShell |
MalwareMafalda | Mafalda can execute PowerShell commands on a compromised machine. |
| T1059.003 Windows Command Shell |
MalwareMafalda | Mafalda can execute shell commands using `cmd.exe`. |
| T1071.001 Web Protocols |
MalwareMafalda | Mafalda can use HTTP for C2. |
| T1074.001 Local Data Staging |
MalwareMafalda | Mafalda can place retrieved files into a destination directory. |
| T1082 System Information Discovery |
MalwareMafalda | Mafalda can collect the computer name of a compromised host. |
| T1083 File and Directory Discovery |
MalwareMafalda | Mafalda can search for files and directories. |
| T1090.001 Internal Proxy |
MalwareMafalda | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareMafalda | Mafalda can use raw TCP for C2. |
| T1105 Ingress Tool Transfer |
MalwareMafalda | Mafalda can download additional files onto the compromised host. |
| T1106 Native API |
MalwareMafalda | Mafalda can use a variety of API calls. |
| T1112 Modify Registry |
MalwareMafalda | Mafalda can manipulate the system registry on a compromised host. |
| T1113 Screen Capture |
MalwareMafalda | Mafalda can take a screenshot of the target machine and save it to a file. |
| T1132.001 Standard Encoding |
MalwareMafalda | Mafalda can encode data using Base64 prior to exfiltration. |
| T1133 External Remote Services |
MalwareMafalda | Mafalda can establish an SSH connection from a compromised host to a server. |
| T1134 Access Token Manipulation |
MalwareMafalda | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges. |
| T1134.003 Make and Impersonate Token |
MalwareMafalda | Mafalda can create a token for a different user. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMafalda | Mafalda can decrypt files and data. |
| T1205.001 Port Knocking |
MalwareMafalda | Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server. |
| T1217 Browser Information Discovery |
MalwareMafalda | Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file. |
| T1518.001 Security Software Discovery |
MalwareMafalda | Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools. |
| T1552.004 Private Keys |
MalwareMafalda | Mafalda can collect a Chrome encryption key used to protect browser cookies. |
| T1569.002 Service Execution |
MalwareMafalda | Mafalda can create a remote service, let it run once, and then delete it. |
| T1573.001 Symmetric Cryptography |
MalwareMafalda | Mafalda can encrypt its C2 traffic with RC4. |
| T1622 Debugger Evasion |
MalwareMafalda | Mafalda can search for debugging tools on a compromised host. |
| T1680 Local Storage Discovery |
MalwareMafalda | Mafalda can enumerate all drives on a compromised host. |
| T1685.005 Clear Windows Event Logs |
MalwareMafalda | Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.