ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1068×

21 examples

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareBlackCat

BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks.

T1033
System Owner/User Discovery
MalwareBlackCat

BlackCat can utilize `net use` commands to discover the user name on a compromised host.

T1047
Windows Management Instrumentation
MalwareBlackCat

BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.

T1059.003
Windows Command Shell
MalwareBlackCat

BlackCat can execute commands on a compromised network with the use of `cmd.exe`.

T1069.002
Domain Groups
MalwareBlackCat

BlackCat can determine if a user on a compromised host has domain admin privileges.

T1082
System Information Discovery
MalwareBlackCat

BlackCat can obtain the computer name and UUID.

T1083
File and Directory Discovery
MalwareBlackCat

BlackCat can enumerate files for encryption.

T1087.002
Domain Account
MalwareBlackCat

BlackCat can utilize `net use` commands to identify domain users.

T1112
Modify Registry
MalwareBlackCat

BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`

T1134
Access Token Manipulation
MalwareBlackCat

BlackCat has the ability modify access tokens.

T1135
Network Share Discovery
MalwareBlackCat

BlackCat has the ability to discover network shares on compromised networks.

T1222.001
Windows Permissions
MalwareBlackCat

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

T1486
Data Encrypted for Impact
MalwareBlackCat

BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances.

T1489
Service Stop
MalwareBlackCat

BlackCat has the ability to stop VM services on compromised networks.

T1490
Inhibit System Recovery
MalwareBlackCat

BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`.

T1491.001
Internal Defacement
MalwareBlackCat

BlackCat can change the desktop wallpaper on compromised hosts.

T1548.002
Bypass User Account Control
MalwareBlackCat

BlackCat can bypass UAC to escalate privileges.

T1561.001
Disk Content Wipe
MalwareBlackCat

BlackCat has the ability to wipe VM snapshots on compromised networks.

T1570
Lateral Tool Transfer
MalwareBlackCat

BlackCat can replicate itself across connected servers via `psexec`.

T1680
Local Storage Discovery
MalwareBlackCat

BlackCat can enumerate local drives.

T1685.005
Clear Windows Event Logs
MalwareBlackCat

BlackCat can clear Windows event logs using `wevtutil.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.