ATT&CKReferencesSentinelLabs Metador Technical Appendix Sept 2022

SentinelLabs Metador Technical Appendix Sept 2022

SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples41

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareMafalda

Mafalda can dump password hashes from `LSASS.exe`.

T1005
Data from Local System
MalwaremetaMain

metaMain can collect files and system information from a compromised host.

T1012
Query Registry
MalwareMafalda

Mafalda can enumerate Registry keys with all subkeys and values.

T1027.013
Encrypted/Encoded File
MalwaremetaMain

metaMain's module file has been encrypted via XOR.

T1033
System Owner/User Discovery
MalwareMafalda

Mafalda can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwaremetaMain

metaMain can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel
MalwaremetaMain

metaMain can upload collected files and data to its C2 server.

T1056
Input Capture
MalwaremetaMain

metaMain can log mouse events.

T1056
Input Capture
MalwareMafalda

Mafalda can conduct mouse event logging.

T1056.001
Keylogging
MalwaremetaMain

metaMain has the ability to log keyboard events.

T1057
Process Discovery
MalwaremetaMain

metaMain can enumerate the processes that run on the platform.

T1059.001
PowerShell
MalwareMafalda

Mafalda can execute PowerShell commands on a compromised machine.

T1059.003
Windows Command Shell
MalwareMafalda

Mafalda can execute shell commands using `cmd.exe`.

T1070.004
File Deletion
MalwaremetaMain

metaMain has deleted collected items after uploading the content to its C2 server.

T1070.006
Timestomp
MalwaremetaMain

metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges.

T1071.001
Web Protocols
MalwaremetaMain

metaMain can use HTTP for C2 communications.

T1074.001
Local Data Staging
MalwaremetaMain

metaMain has stored the collected system files in a working directory.

T1082
System Information Discovery
MalwareMafalda

Mafalda can collect the computer name of a compromised host.

T1082
System Information Discovery
MalwaremetaMain

metaMain can collect the computer name from a compromised host.

T1083
File and Directory Discovery
MalwaremetaMain

metaMain can recursively enumerate files in an operator-provided directory.

T1090.001
Internal Proxy
MalwareMafalda

Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1090.001
Internal Proxy
MalwaremetaMain

metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server.

T1095
Non-Application Layer Protocol
MalwaremetaMain

metaMain can establish an indirect and raw TCP socket-based connection to the C2 server.

T1105
Ingress Tool Transfer
MalwareMafalda

Mafalda can download additional files onto the compromised host.

T1105
Ingress Tool Transfer
MalwaremetaMain

metaMain can download files onto compromised systems.

T1106
Native API
MalwaremetaMain

metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`.

T1112
Modify Registry
MalwaremetaMain

metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity.

T1112
Modify Registry
MalwareMafalda

Mafalda can manipulate the system registry on a compromised host.

T1113
Screen Capture
MalwaremetaMain

metaMain can take and save screenshots.

T1132.001
Standard Encoding
MalwareMafalda

Mafalda can encode data using Base64 prior to exfiltration.

T1133
External Remote Services
MalwareMafalda

Mafalda can establish an SSH connection from a compromised host to a server.

T1134
Access Token Manipulation
MalwareMafalda

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.

T1134.003
Make and Impersonate Token
MalwareMafalda

Mafalda can create a token for a different user.

T1205.001
Port Knocking
MalwareMafalda

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.

T1497.003
Time Based Checks
MalwaremetaMain

metaMain has delayed execution for five to six minutes during its persistence establishment process.

T1518.001
Security Software Discovery
MalwareMafalda

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.

T1569.002
Service Execution
MalwareMafalda

Mafalda can create a remote service, let it run once, and then delete it.

T1573.001
Symmetric Cryptography
MalwaremetaMain

metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm.

T1574.001
DLL
MalwaremetaMain

metaMain can support an HKCMD sideloading start method.

T1622
Debugger Evasion
MalwareMafalda

Mafalda can search for debugging tools on a compromised host.

T1680
Local Storage Discovery
MalwareMafalda

Mafalda can enumerate all drives on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.