ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1229×

29 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1016
System Network Configuration Discovery
MalwareHavoc

Havoc has a module for network enumeration including determining IP addresses.

T1016.001
Internet Connection Discovery
MalwareHavoc

The Havoc demon can check for a connection to the C2 server from the target machine.

T1018
Remote System Discovery
MalwareHavoc

Havoc features a module capable of host enumeration.

T1027.010
Command Obfuscation
MalwareHavoc

Havoc has utilized XOR encryption with the key “01-01-1900” to obfuscate command strings.

T1033
System Owner/User Discovery
MalwareHavoc

Havoc can trigger exection of `whoami` on the target host to display the current user.

T1055.001
Dynamic-link Library Injection
MalwareHavoc

Havoc has DLL spawn and injection modules.

T1055.002
Portable Executable Injection
MalwareHavoc

Havoc has itself injected into `C:\\Windows\\System32\\Werfault.exe` on targeted systems.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1059.001
PowerShell
MalwareHavoc

Havoc can facilitate the execution of PowerShell commands.

T1059.003
Windows Command Shell
MalwareHavoc

Havoc can execute commands via `cmd.exe`.

T1071.001
Web Protocols
MalwareHavoc

Havoc can use HTTP/S listeners to establish and maintain C2 communications.

T1071.002
File Transfer Protocols
MalwareHavoc

Havoc can use an SMB listener for C2 communication.

T1082
System Information Discovery
MalwareHavoc

Havoc can gather system information including hostname, domain, and OS details.

T1083
File and Directory Discovery
MalwareHavoc

The Havoc interface can display a file explorer view of the compromised host.

T1087
Account Discovery
MalwareHavoc

Havoc can identify privileged user accounts on infected systems.

T1090
Proxy
MalwareHavoc

Havoc has the ability to route HTTP/S communications through designated proxies.

T1105
Ingress Tool Transfer
MalwareHavoc

Havoc has the ability to upload files to infected systems.

T1106
Native API
MalwareHavoc

Havoc can use `NtAllocateVirtualMemory` and `NtCreateThreadEx` to aid process injection.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

T1134.001
Token Impersonation/Theft
MalwareHavoc

Havoc has a module capable of token impersonation.

T1204.002
Malicious File
MalwareHavoc

Havoc has been executed by victims through the use of targeted lures and crafted decoy documents.

T1204.004
Malicious Copy and Paste
MalwareHavoc

The Havoc infection chain has been initiated via ClickFix lures in phishing emails.

T1497.003
Time Based Checks
MalwareHavoc

The Havoc demon agent can be set to sleep for a specified time.

T1559
Inter-Process Communication
MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

T1566.002
Spearphishing Link
MalwareHavoc

Havoc has been distributed through ClickFix phishing campaigns.

T1570
Lateral Tool Transfer
MalwareHavoc

Havoc has the ability to copy files from one location to another.

T1573.001
Symmetric Cryptography
MalwareHavoc

Havoc can send an AES encrypted check-in request to the C2 server.

T1574.001
DLL
MalwareHavoc

Havoc has leveraged legitimate executables to side-load malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.