ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCrimson

Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.

T1012
Query Registry
MalwareTEARDROP

TEARDROP checked that HKU\SOFTWARE\Microsoft\CTF existed before decoding its embedded payload.

T1012
Query Registry
MalwareDUSTTRAP

DUSTTRAP can enumerate Registry items.

T1012
Query Registry
MalwarePUBLOAD

PUBLOAD has queried Registry values to identify software using `reg query`.

T1012
Query Registry
MalwareWoody RAT

Woody RAT can search registry keys to identify antivirus programs on an compromised host.

T1012
Query Registry
MalwareMafalda

Mafalda can enumerate Registry keys with all subkeys and values.

T1012
Query Registry
MalwareHOPLIGHT

A variant of HOPLIGHT hooks lsass.exe, and lsass.exe then checks the Registry for the data value 'rdpproto' under the key SYSTEM\CurrentControlSet\Control\Lsa Name.

T1012
Query Registry
MalwareWastedLocker

WastedLocker checks for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.

T1012
Query Registry
MalwareInvisiMole

InvisiMole can enumerate Registry values, keys, and data.

T1012
Query Registry
MalwareVolgmer

Volgmer checks the system for certain Registry keys.

T1012
Query Registry
MalwareTRANSLATEXT

TRANSLATEXT has queried the following registry key to check for installed Chrome extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist `.

T1012
Query Registry
MalwareFatDuke

FatDuke can get user agent strings for the default browser from HKCU\Software\Classes\http\shell\open\command.

T1012
Query Registry
MalwareLucifer

Lucifer can check for existing stratum cryptomining information in HKLM\Software\Microsoft\Windows\CurrentVersion\spreadCpuXmr – %stratum info%.

T1012
Query Registry
MalwareRising Sun

Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`.

T1012
Query Registry
MalwareROKRAT

ROKRAT can access the HKLM\System\CurrentControlSet\Services\mssmbios\Data\SMBiosData Registry key to obtain the System manufacturer value to identify the machine type.

T1012
Query Registry
MalwareDarkWatchman

DarkWatchman can query the Registry to determine if it has already been installed on the system.

T1012
Query Registry
MalwarePlugX

PlugX can enumerate and query for information contained within the Windows Registry.

T1012
Query Registry
MalwareReaver

Reaver queries the Registry to determine the correct Startup path to use for persistence.

T1012
Query Registry
MalwareBisonal

Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry.

T1012
Query Registry
MalwareEpic

Epic uses the rem reg query command to obtain values from Registry keys.

T1012
Query Registry
MalwareClambling

Clambling has the ability to enumerate Registry keys, including KEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt\strDataDir to search for a bitcoin wallet.

T1012
Query Registry
MalwareSVCReady

SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information.

T1012
Query Registry
MalwareCarbanak

Carbanak checks the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings for proxy configurations information.

T1012
Query Registry
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys.

T1012
Query Registry
MalwareSaint Bot

Saint Bot has used `check_registry_keys` as part of its environmental checks.

T1012
Query Registry
MalwareCharmPower

CharmPower has the ability to enumerate `Uninstall` registry values.

T1012
Query Registry
MalwareMori

Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and
`HKLM\Software\NFC\`.

T1012
Query Registry
MalwareQUADAGENT

QUADAGENT checks if a value exists within a Registry key in the HKCU hive whose name is the same as the scheduled task it has created.

T1012
Query Registry
MalwareBendyBear

BendyBear can query the host's Registry key at HKEY_CURRENT_USER\Console\QuickEdit to retrieve data.

T1012
Query Registry
MalwareUroburos

Uroburos can query the Registry, typically `HKLM:\SOFTWARE\Classes\.wav\OpenWithProgIds`, to find the key and path to decrypt and load its kernel driver and kernel driver loader.

T1012
Query Registry
Malwaregh0st RAT

gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system.

T1012
Query Registry
MalwareShamoon

Shamoon queries several Registry keys to identify hard disk partitions to overwrite.

T1012
Query Registry
MalwareRedLine Stealer

RedLine Stealer can query the Windows Registry.

T1012
Query Registry
MalwareStoneDrill

StoneDrill has looked in the registry to find the default browser path.

T1012
Query Registry
MalwareAttor

Attor has opened the registry and performed query searches.

T1012
Query Registry
MalwareLitePower

LitePower can query the Registry for keys added to execute COM hijacking.

T1012
Query Registry
MalwareQUIETCANARY

QUIETCANARY has the ability to retrieve information from the Registry.

T1012
Query Registry
MalwareDerusbi

Derusbi is capable of enumerating Registry keys and values.

T1012
Query Registry
MalwareBlackByte Ransomware

BlackByte Ransomware enumerates the Registry, specifically the `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options` key.

T1012
Query Registry
MalwareSodaMaster

SodaMaster has the ability to query the Registry to detect a key specific to VMware.

T1012
Query Registry
MalwareLiteDuke

LiteDuke can query the Registry to check for the presence of HKCU\Software\KasperskyLab.

T1012
Query Registry
MalwareSibot

Sibot has queried the registry for proxy server information.

T1012
Query Registry
MalwareZxxZ

ZxxZ can search the registry of a compromised host.

T1012
Query Registry
MalwareWINDSHIELD

WINDSHIELD can gather Registry values.

T1012
Query Registry
MalwareShark

Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1012
Query Registry
MalwareBazar

Bazar can query Windows\CurrentVersion\Uninstall for installed applications.

T1012
Query Registry
MalwareRATANKBA

RATANKBA uses the command reg query “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings”.

T1012
Query Registry
MalwareKapeka

Kapeka queries registry values for stored configuration information.

T1012
Query Registry
MalwareZebrocy

Zebrocy executes the reg query command to obtain information in the Registry.

T1012
Query Registry
MalwareFinFisher

FinFisher queries Registry values as part of its anti-sandbox checks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.