Real-world descriptions of how a group, tool or campaign used a technique.
33 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to upload files from a compromised system. |
| T1021 Remote Services |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use RPC for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| T1021.006 Windows Remote Management |
ToolBrute Ratel C4 | Brute Ratel C4 can use WinRM for pivoting. |
| T1027 Obfuscated Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory. |
| T1027.007 Dynamic API Resolution |
ToolBrute Ratel C4 | Brute Ratel C4 can call and dynamically resolve hashed APIs. |
| T1036.005 Match Legitimate Resource Name or Location |
ToolBrute Ratel C4 | Brute Ratel C4 has used a payload file named OneDrive.update to appear benign. |
| T1036.008 Masquerade File Type |
ToolBrute Ratel C4 | Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files. |
| T1046 Network Service Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can conduct port scanning against targeted systems. |
| T1047 Windows Management Instrumentation |
ToolBrute Ratel C4 | Brute Ratel C4 can use WMI to move laterally. |
| T1055.002 Portable Executable Injection |
ToolBrute Ratel C4 | Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts. |
| T1057 Process Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs). |
| T1059.003 Windows Command Shell |
ToolBrute Ratel C4 | Brute Ratel C4 can use cmd.exe for execution. |
| T1069.002 Domain Groups |
ToolBrute Ratel C4 | Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1071.001 Web Protocols |
ToolBrute Ratel C4 | Brute Ratel C4 can use HTTPS and HTTPS for C2 communication. |
| T1071.004 DNS |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1087.002 Domain Account |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| T1095 Non-Application Layer Protocol |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use TCP for external C2. |
| T1102 Web Service |
ToolBrute Ratel C4 | Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams. |
| T1105 Ingress Tool Transfer |
ToolBrute Ratel C4 | Brute Ratel C4 can download files to compromised hosts. |
| T1106 Native API |
ToolBrute Ratel C4 | Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion. |
| T1113 Screen Capture |
ToolBrute Ratel C4 | Brute Ratel C4 can take screenshots on compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to deobfuscate its payload prior to execution. |
| T1204.002 Malicious File |
ToolBrute Ratel C4 | Brute Ratel C4 has gained execution through users opening malicious documents. |
| T1482 Domain Trust Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery. |
| T1497.003 Time Based Checks |
ToolBrute Ratel C4 | Brute Ratel C4 can call `NtDelayExecution` to pause execution. |
| T1518.001 Security Software Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can detect EDR userland hooks. |
| T1558.003 Kerberoasting |
ToolBrute Ratel C4 | Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking. |
| T1569.002 Service Execution |
ToolBrute Ratel C4 | Brute Ratel C4 can create Windows system services for execution. |
| T1572 Protocol Tunneling |
ToolBrute Ratel C4 | Brute Ratel C4 can use DNS over HTTPS for C2. |
| T1574.001 DLL |
ToolBrute Ratel C4 | Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe. |
| T1620 Reflective Code Loading |
ToolBrute Ratel C4 | Brute Ratel C4 has used reflective loading to execute malicious DLLs. |
| T1685 Disable or Modify Tools |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.