ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1159×

29 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDUSTTRAP

DUSTTRAP can gather data from infected systems.

T1010
Application Window Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running application windows.

T1012
Query Registry
MalwareDUSTTRAP

DUSTTRAP can enumerate Registry items.

T1016
System Network Configuration Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate infected system network information.

T1018
Remote System Discovery
MalwareDUSTTRAP

DUSTTRAP can use `ping` to identify remote hosts within the victim network.

T1027.009
Embedded Payloads
MalwareDUSTTRAP

DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution.

T1027.013
Encrypted/Encoded File
MalwareDUSTTRAP

DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory.

T1041
Exfiltration Over C2 Channel
MalwareDUSTTRAP

DUSTTRAP can exfiltrate collected data over C2 channels.

T1055
Process Injection
MalwareDUSTTRAP

DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins.

T1056.001
Keylogging
MalwareDUSTTRAP

DUSTTRAP can perform keylogging operations.

T1057
Process Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running processes.

T1059.003
Windows Command Shell
MalwareDUSTTRAP

DUSTTRAP can execute commands via `cmd.exe`.

T1070
Indicator Removal
MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070.005
Network Share Connection Removal
MalwareDUSTTRAP

DUSTTRAP can remove network shares from infected systems.

T1082
System Information Discovery
MalwareDUSTTRAP

DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value.

T1083
File and Directory Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate files and directories.

T1087.001
Local Account
MalwareDUSTTRAP

DUSTTRAP can enumerate local user accounts.

T1087.002
Domain Account
MalwareDUSTTRAP

DUSTTRAP can enumerate domain accounts.

T1105
Ingress Tool Transfer
MalwareDUSTTRAP

DUSTTRAP can retrieve and load additional payloads.

T1113
Screen Capture
MalwareDUSTTRAP

DUSTTRAP can capture screenshots.

T1124
System Time Discovery
MalwareDUSTTRAP

DUSTTRAP reads the infected system's current time and writes it to a log file during execution.

T1135
Network Share Discovery
MalwareDUSTTRAP

DUSTTRAP can identify and enumerate victim system network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareDUSTTRAP

DUSTTRAP deobfuscates embedded payloads.

T1482
Domain Trust Discovery
MalwareDUSTTRAP

DUSTTRAP can identify Active Directory information and related items.

T1497.001
System Checks
MalwareDUSTTRAP

DUSTTRAP decryption relies on the infected machine's `HKLM\SOFTWARE\Microsoft\Cryptography\MachineGUID` value.

T1518.001
Security Software Discovery
MalwareDUSTTRAP

DUSTTRAP can identify security software.

T1615
Group Policy Discovery
MalwareDUSTTRAP

DUSTTRAP can identify victim environment Group Policy information.

T1654
Log Enumeration
MalwareDUSTTRAP

DUSTTRAP can identify infected system log information.

T1685.005
Clear Windows Event Logs
MalwareDUSTTRAP

DUSTTRAP can delete infected system log information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.