MITRE ATT&CK Coverage
Every technique identified across the analyses in this project, mapped to the
MITRE ATT&CK framework and grouped by tactic. 46 techniques
across 5 malware families — click any family to jump to the analysis where it is described
in detail.
| Family |
Type |
Techniques |
Analysis |
| Emotet |
Loader / banking trojan |
16 |
Read |
| XLoader 4.3 |
Infostealer / form grabber |
16 |
Read |
| NanoCore 1.2.2.0 |
Remote access trojan |
17 |
Read |
| Ryuk |
Ransomware |
11 |
Read |
| MedusaLocker |
Ransomware |
9 |
Read |
CrackedHaven is a software-piracy awareness case
study rather than a malware analysis, so it carries no ATT&CK mapping.
Initial Access
| Technique |
ID |
Families |
| Phishing: Spearphishing Attachment |
T1566.001 |
Emotet |
Execution
| Technique |
ID |
Families |
| Command and Scripting Interpreter: Visual Basic |
T1059.005 |
Emotet |
Persistence
| Technique |
ID |
Families |
| Boot or Logon Autostart Execution: Registry Run Keys |
T1547.001 |
NanoCore, Ryuk, XLoader |
| Scheduled Task/Job: Scheduled Task |
T1053.005 |
MedusaLocker, NanoCore |
Privilege Escalation
| Technique |
ID |
Families |
| Abuse Elevation Control Mechanism |
T1548 |
XLoader |
| Abuse Elevation Control Mechanism: Bypass User Account Control |
T1548.002 |
MedusaLocker |
| Access Token Manipulation |
T1134 |
Ryuk |
Defense Evasion
| Technique |
ID |
Families |
| Obfuscated Files or Information |
T1027 |
Emotet, Ryuk |
| Obfuscated Files or Information: Software Packing |
T1027.002 |
NanoCore, XLoader |
| Obfuscated Files or Information: Dynamic API Resolution |
T1027.007 |
Emotet, NanoCore, Ryuk |
| Obfuscated Files or Information: Encrypted/Encoded File |
T1027.013 |
XLoader |
| Deobfuscate/Decode Files or Information |
T1140 |
Emotet |
| Reflective Code Loading |
T1620 |
Emotet, XLoader |
| Process Injection: Portable Executable Injection |
T1055.002 |
Ryuk |
| Process Injection: Process Hollowing |
T1055.012 |
NanoCore, XLoader |
| Impair Defenses: Disable or Modify Tools |
T1562.001 |
MedusaLocker, NanoCore, XLoader |
| Indicator Removal: File Deletion |
T1070.004 |
Emotet, Ryuk, XLoader |
| Subvert Trust Controls: Mark-of-the-Web Bypass |
T1553.005 |
Emotet, NanoCore |
| System Binary Proxy Execution: Regsvr32 |
T1218.010 |
Emotet |
| System Binary Proxy Execution: Rundll32 |
T1218.011 |
Emotet |
| Masquerading: Masquerade Task or Service |
T1036.004 |
NanoCore |
| Masquerading: Match Legitimate Name or Location |
T1036.005 |
Emotet |
| Hide Artifacts: Hidden Window |
T1564.003 |
NanoCore |
| Hide Artifacts: Resource Forking |
T1564.009 |
NanoCore |
| File and Directory Permissions Modification: Windows |
T1222.001 |
NanoCore |
| Virtualization/Sandbox Evasion |
T1497 |
XLoader |
Credential Access
| Technique |
ID |
Families |
| Credentials from Password Stores: Web Browsers |
T1555.003 |
XLoader |
| Input Capture |
T1056 |
XLoader |
| Input Capture: Keylogging |
T1056.001 |
NanoCore |
Discovery
| Technique |
ID |
Families |
| Process Discovery |
T1057 |
Ryuk, XLoader |
| System Information Discovery |
T1082 |
Emotet, XLoader |
| Network Share Discovery |
T1135 |
MedusaLocker, Ryuk |
Lateral Movement
| Technique |
ID |
Families |
| Remote Services: SMB/Windows Admin Shares |
T1021.002 |
MedusaLocker |
Collection
| Technique |
ID |
Families |
| Clipboard Data |
T1115 |
NanoCore, XLoader |
| Data from Local System |
T1005 |
NanoCore |
| Automated Collection |
T1119 |
NanoCore |
Command and Control
| Technique |
ID |
Families |
| Application Layer Protocol: Web Protocols |
T1071.001 |
Emotet, XLoader |
| Non-Application Layer Protocol |
T1095 |
NanoCore |
| Encrypted Channel: Asymmetric Cryptography |
T1573.002 |
Emotet |
| Data Encoding: Standard Encoding |
T1132.001 |
Emotet |
| Ingress Tool Transfer |
T1105 |
Emotet |
Exfiltration
| Technique |
ID |
Families |
| Exfiltration Over C2 Channel |
T1041 |
NanoCore, XLoader |
Impact
| Technique |
ID |
Families |
| Data Encrypted for Impact |
T1486 |
MedusaLocker, Ryuk |
| Service Stop |
T1489 |
MedusaLocker, Ryuk |
| Inhibit System Recovery |
T1490 |
MedusaLocker, Ryuk |
| Defacement: Internal Defacement |
T1491.001 |
MedusaLocker |
Recreated TTPs
Techniques that ship with buildable source code, and where available a detection rule or
query. Links point to the write-up first, then the code.
MedusaLocker
Every recreated technique here has an accompanying detection page with Sysmon, Defender and
audit-log screenshots.
NanoCore
XLoader
Ryuk
Emotet
Candidate techniques are identified but not yet implemented — see the
planned TTPs.
Contributions welcome via
CONTRIBUTING.md.
Notes on the mapping
- Techniques are recorded as mapped in each analysis. Where one family was mapped to a
parent technique and another to a sub-technique of it (for example
T1548 and T1548.002,
or T1056 and T1056.001), both are listed rather than silently merged.
- A family appearing against a technique means the behaviour was observed during analysis,
not merely suspected. Where a behaviour was present only as embedded strings and never seen
executing — Ryuk’s service termination, for instance — that caveat is stated in the analysis.
- Counts in the summary table are distinct techniques per family, so they do not sum to 46:
many techniques are shared across families.
← Back to all analyses