ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1146×

17 examples

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareMgBot

MgBot includes modules for dumping and capturing credentials from process memory.

T1005
Data from Local System
MalwareMgBot

MgBot includes modules for collecting files from local systems based on a given set of properties and filenames.

T1018
Remote System Discovery
MalwareMgBot

MgBot includes modules for performing ARP scans of local connected systems.

T1025
Data from Removable Media
MalwareMgBot

MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria.

T1033
System Owner/User Discovery
MalwareMgBot

MgBot includes modules for identifying local users and administrators on victim machines.

T1046
Network Service Discovery
MalwareMgBot

MgBot includes modules for performing HTTP and server service scans.

T1056.001
Keylogging
MalwareMgBot

MgBot includes keylogger payloads focused on the QQ chat application.

T1057
Process Discovery
MalwareMgBot

MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running.

T1087.001
Local Account
MalwareMgBot

MgBot includes modules for identifying local administrator accounts on victim systems.

T1087.002
Domain Account
MalwareMgBot

MgBot includes modules for collecting information on Active Directory domain accounts.

T1115
Clipboard Data
MalwareMgBot

MgBot can capture clipboard data.

T1123
Audio Capture
MalwareMgBot

MgBot can capture input and output audio streams from infected devices.

T1213.006
Databases
MalwareMgBot

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

T1482
Domain Trust Discovery
MalwareMgBot

MgBot includes modules for collecting information on local domain users and permissions.

T1539
Steal Web Session Cookie
MalwareMgBot

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

T1555
Credentials from Password Stores
MalwareMgBot

MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.