Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDUSTTRAP | DUSTTRAP can gather data from infected systems. |
| T1010 Application Window Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running application windows. |
| T1012 Query Registry |
MalwareDUSTTRAP | DUSTTRAP can enumerate Registry items. |
| T1016 System Network Configuration Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate infected system network information. |
| T1018 Remote System Discovery |
MalwareDUSTTRAP | DUSTTRAP can use `ping` to identify remote hosts within the victim network. |
| T1027.009 Embedded Payloads |
MalwareDUSTTRAP | DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution. |
| T1027.013 Encrypted/Encoded File |
MalwareDUSTTRAP | DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory. |
| T1041 Exfiltration Over C2 Channel |
MalwareDUSTTRAP | DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1055 Process Injection |
MalwareDUSTTRAP | DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins. |
| T1056.001 Keylogging |
MalwareDUSTTRAP | DUSTTRAP can perform keylogging operations. |
| T1057 Process Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running processes. |
| T1059.003 Windows Command Shell |
MalwareDUSTTRAP | DUSTTRAP can execute commands via `cmd.exe`. |
| T1070 Indicator Removal |
MalwareDUSTTRAP | DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070.005 Network Share Connection Removal |
MalwareDUSTTRAP | DUSTTRAP can remove network shares from infected systems. |
| T1082 System Information Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value. |
| T1083 File and Directory Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate files and directories. |
| T1087.001 Local Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate local user accounts. |
| T1087.002 Domain Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate domain accounts. |
| T1105 Ingress Tool Transfer |
MalwareDUSTTRAP | DUSTTRAP can retrieve and load additional payloads. |
| T1113 Screen Capture |
MalwareDUSTTRAP | DUSTTRAP can capture screenshots. |
| T1124 System Time Discovery |
MalwareDUSTTRAP | DUSTTRAP reads the infected system's current time and writes it to a log file during execution. |
| T1135 Network Share Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify and enumerate victim system network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDUSTTRAP | DUSTTRAP deobfuscates embedded payloads. |
| T1482 Domain Trust Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify Active Directory information and related items. |
| T1497.001 System Checks |
MalwareDUSTTRAP | DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value. |
| T1518.001 Security Software Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify security software. |
| T1615 Group Policy Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify victim environment Group Policy information. |
| T1654 Log Enumeration |
MalwareDUSTTRAP | DUSTTRAP can identify infected system log information. |
| T1685.005 Clear Windows Event Logs |
MalwareDUSTTRAP | DUSTTRAP can delete infected system log information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.