ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1071×

10 examples

TechniqueUsed byProcedure example
T1071
Application Layer Protocol
MalwareHildegard

Hildegard has used an IRC channel for C2 communications.

T1071
Application Layer Protocol
MalwareQUIETEXIT

QUIETEXIT can use an inverse negotiated SSH connection as part of its C2.

T1071
Application Layer Protocol
MalwareRaspberry Robin

Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads.

T1071
Application Layer Protocol
MalwareSiloscape

Siloscape connects to an IRC server for C2.

T1071
Application Layer Protocol
MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

T1071
Application Layer Protocol
MalwareNETEAGLE

Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519.

T1071
Application Layer Protocol
MalwareLucifer

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

T1071
Application Layer Protocol
MalwareClambling

Clambling has the ability to use Telnet for communication.

T1071
Application Layer Protocol
ToolSliver

Sliver can utilize the Wireguard VPN protocol for command and control.

T1071
Application Layer Protocol
MalwareDuqu

Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.