Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Mafalda can dump password hashes from `LSASS.exe`. |
| T1005 Data from Local System |
Mafalda can collect files and information from a compromised host. |
| T1012 Query Registry |
Mafalda can enumerate Registry keys with all subkeys and values. |
| T1016 System Network Configuration Discovery |
Mafalda can use the `GetAdaptersInfo` function to retrieve information about network adapters and the `GetIpNetTable` function to retrieve the IPv4 to physical network address mapping table. |
| T1027.013 Encrypted/Encoded File |
Mafalda has been obfuscated and contains encrypted functions. |
| T1033 System Owner/User Discovery |
Mafalda can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
Mafalda can send network system data and files to its C2 server. |
| T1049 System Network Connections Discovery |
Mafalda can use the |
| T1056 Input Capture |
Mafalda can conduct mouse event logging. |
| T1057 Process Discovery |
Mafalda can enumerate running processes on a machine. |
| T1059.001 PowerShell |
Mafalda can execute PowerShell commands on a compromised machine. |
| T1059.003 Windows Command Shell |
Mafalda can execute shell commands using `cmd.exe`. |
| T1071.001 Web Protocols |
Mafalda can use HTTP for C2. |
| T1074.001 Local Data Staging |
Mafalda can place retrieved files into a destination directory. |
| T1082 System Information Discovery |
Mafalda can collect the computer name of a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.