ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1060×

36 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareMafalda

Mafalda can dump password hashes from `LSASS.exe`.

T1005
Data from Local System
MalwareMafalda

Mafalda can collect files and information from a compromised host.

T1012
Query Registry
MalwareMafalda

Mafalda can enumerate Registry keys with all subkeys and values.

T1016
System Network Configuration Discovery
MalwareMafalda

Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table.

T1027.013
Encrypted/Encoded File
MalwareMafalda

Mafalda has been obfuscated and contains encrypted functions.

T1033
System Owner/User Discovery
MalwareMafalda

Mafalda can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareMafalda

Mafalda can send network system data and files to its C2 server.

T1049
System Network Connections Discovery
MalwareMafalda

Mafalda can use the GetExtendedTcpTable function to retrieve information about established TCP connections.

T1056
Input Capture
MalwareMafalda

Mafalda can conduct mouse event logging.

T1057
Process Discovery
MalwareMafalda

Mafalda can enumerate running processes on a machine.

T1059.001
PowerShell
MalwareMafalda

Mafalda can execute PowerShell commands on a compromised machine.

T1059.003
Windows Command Shell
MalwareMafalda

Mafalda can execute shell commands using `cmd.exe`.

T1071.001
Web Protocols
MalwareMafalda

Mafalda can use HTTP for C2.

T1074.001
Local Data Staging
MalwareMafalda

Mafalda can place retrieved files into a destination directory.

T1082
System Information Discovery
MalwareMafalda

Mafalda can collect the computer name of a compromised host.

T1083
File and Directory Discovery
MalwareMafalda

Mafalda can search for files and directories.

T1090.001
Internal Proxy
MalwareMafalda

Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1095
Non-Application Layer Protocol
MalwareMafalda

Mafalda can use raw TCP for C2.

T1105
Ingress Tool Transfer
MalwareMafalda

Mafalda can download additional files onto the compromised host.

T1106
Native API
MalwareMafalda

Mafalda can use a variety of API calls.

T1112
Modify Registry
MalwareMafalda

Mafalda can manipulate the system registry on a compromised host.

T1113
Screen Capture
MalwareMafalda

Mafalda can take a screenshot of the target machine and save it to a file.

T1132.001
Standard Encoding
MalwareMafalda

Mafalda can encode data using Base64 prior to exfiltration.

T1133
External Remote Services
MalwareMafalda

Mafalda can establish an SSH connection from a compromised host to a server.

T1134
Access Token Manipulation
MalwareMafalda

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.

T1134.003
Make and Impersonate Token
MalwareMafalda

Mafalda can create a token for a different user.

T1140
Deobfuscate/Decode Files or Information
MalwareMafalda

Mafalda can decrypt files and data.

T1205.001
Port Knocking
MalwareMafalda

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.

T1217
Browser Information Discovery
MalwareMafalda

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.

T1518.001
Security Software Discovery
MalwareMafalda

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.

T1552.004
Private Keys
MalwareMafalda

Mafalda can collect a Chrome encryption key used to protect browser cookies.

T1569.002
Service Execution
MalwareMafalda

Mafalda can create a remote service, let it run once, and then delete it.

T1573.001
Symmetric Cryptography
MalwareMafalda

Mafalda can encrypt its C2 traffic with RC4.

T1622
Debugger Evasion
MalwareMafalda

Mafalda can search for debugging tools on a compromised host.

T1680
Local Storage Discovery
MalwareMafalda

Mafalda can enumerate all drives on a compromised host.

T1685.005
Clear Windows Event Logs
MalwareMafalda

Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.