Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1071 Application Layer Protocol |
MalwareHildegard | Hildegard has used an IRC channel for C2 communications. |
| T1071 Application Layer Protocol |
MalwareQUIETEXIT | QUIETEXIT can use an inverse negotiated SSH connection as part of its C2. |
| T1071 Application Layer Protocol |
MalwareRaspberry Robin | Raspberry Robin is capable of contacting the TOR network for delivering second-stage payloads. |
| T1071 Application Layer Protocol |
MalwareSiloscape | Siloscape connects to an IRC server for C2. |
| T1071 Application Layer Protocol |
MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1071 Application Layer Protocol |
MalwareNETEAGLE | Adversaries can also use NETEAGLE to establish an RDP connection with a controller over TCP/7519. |
| T1071 Application Layer Protocol |
MalwareLucifer | Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server. |
| T1071 Application Layer Protocol |
MalwareClambling | Clambling has the ability to use Telnet for communication. |
| T1071 Application Layer Protocol |
ToolSliver | Sliver can utilize the Wireguard VPN protocol for command and control. |
| T1071 Application Layer Protocol |
MalwareDuqu | Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.