ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1085×

25 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSardonic

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1007
System Service Discovery
MalwareSardonic

Sardonic has the ability to execute the `net start` command.

T1016
System Network Configuration Discovery
MalwareSardonic

Sardonic has the ability to execute the `ipconfig` command.

T1027
Obfuscated Files or Information
MalwareSardonic

Sardonic can use certain ConfuserEx features for obfuscation and can be encoded in a base64 string.

T1027.010
Command Obfuscation
MalwareSardonic

Sardonic PowerShell scripts can be encrypted with RC4 and compressed using Gzip.

T1047
Windows Management Instrumentation
MalwareSardonic

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1049
System Network Connections Discovery
MalwareSardonic

Sardonic has the ability to execute the `netstat` command.

T1055.004
Asynchronous Procedure Call
MalwareSardonic

Sardonic can use the `QueueUserAPC` API to execute shellcode on a compromised machine.

T1057
Process Discovery
MalwareSardonic

Sardonic has the ability to execute the `tasklist` command.

T1059.001
PowerShell
MalwareSardonic

Sardonic has the ability to execute PowerShell commands on a compromised machine.

T1059.003
Windows Command Shell
MalwareSardonic

Sardonic has the ability to run `cmd.exe` or other interactive processes on a compromised computer.

T1070
Indicator Removal
MalwareSardonic

Sardonic has the ability to delete created WMI objects to evade detections.

T1082
System Information Discovery
MalwareSardonic

Sardonic has the ability to collect the computer name, and CPU manufacturer name from a compromised machine. Sardonic also has the ability to execute the `ver` and `systeminfo` commands.

T1095
Non-Application Layer Protocol
MalwareSardonic

Sardonic can communicate with actor-controlled C2 servers by using a custom little-endian binary protocol.

T1105
Ingress Tool Transfer
MalwareSardonic

Sardonic has the ability to upload additional malicious files to a compromised machine.

T1106
Native API
MalwareSardonic

Sardonic has the ability to call Win32 API functions to determine if `powershell.exe` is running.

T1132.001
Standard Encoding
MalwareSardonic

Sardonic can encode client ID data in 32 uppercase hex characters and transfer to the actor-controlled C2 server.

T1135
Network Share Discovery
MalwareSardonic

Sardonic has the ability to execute the `net view` command.

T1140
Deobfuscate/Decode Files or Information
MalwareSardonic

Sardonic can first decrypt with the RC4 algorithm using a hardcoded decryption key before decompressing.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSardonic

Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence.

T1571
Non-Standard Port
MalwareSardonic

Sardonic has the ability to connect with actor-controlled C2 servers using a custom binary protocol over port 443.

T1573.001
Symmetric Cryptography
MalwareSardonic

Sardonic has the ability to use an RC4 key to encrypt communications to and from actor-controlled C2 servers.

T1573.002
Asymmetric Cryptography
MalwareSardonic

Sardonic has the ability to send a random 64-byte RC4 key to communicate with actor-controlled C2 servers by using an RSA public key.

T1620
Reflective Code Loading
MalwareSardonic

Sardonic has a plugin system that can load specially made DLLs into memory and execute their functions.

T1680
Local Storage Discovery
MalwareSardonic

Sardonic has the ability to collect the C:\ drive serial number from a compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.