| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
The DCRAT configuration file is encrypted using AES-256. |
| T1056.001 Keylogging |
DCRAT can log keystrokes on targeted systems. |
| T1573.002 Asymmetric Cryptography |
DCRAT can use certificate-based authentication for C2 servers. |
| T1685 Disable or Modify Tools |
DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.