Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBADFLICK | BADFLICK has uploaded files from victims' machines. |
| T1006 Direct Volume Access |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing |
| T1006 Direct Volume Access |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file. |
| T1006 Direct Volume Access |
GroupVolt Typhoon | Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| T1006 Direct Volume Access |
GroupScattered Spider | Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file. |
| T1006 Direct Volume Access |
Toolesentutl | esentutl can use the Volume Shadow Copy service to copy locked files such as `ntds.dit`. |
| T1007 System Service Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance. |
| T1007 System Service Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors. |
| T1007 System Service Discovery |
GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1007 System Service Discovery |
GroupKimsuky | Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system. |
| T1007 System Service Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: |
| T1007 System Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used `net start` to list running services. |
| T1007 System Service Discovery |
GroupTeamTNT | TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them. |
| T1007 System Service Discovery |
GroupOilRig | OilRig has used |
| T1007 System Service Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| T1007 System Service Discovery |
GroupKe3chang | Ke3chang performs service discovery using |
| T1007 System Service Discovery |
GroupAPT1 | APT1 used the commands |
| T1007 System Service Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1007 System Service Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group discovers all running services. |
| T1007 System Service Discovery |
GroupChimera | Chimera has used |
| T1007 System Service Discovery |
GroupMirrorFace | MirrorFace has used Tasklist for discovery post compromise. |
| T1007 System Service Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1007 System Service Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1007 System Service Discovery |
MalwareTrickBot | TrickBot collects a list of install programs and services on the system’s machine. |
| T1007 System Service Discovery |
MalwareSynAck | SynAck enumerates all running services. |
| T1007 System Service Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net start` command. |
| T1007 System Service Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1007 System Service Discovery |
MalwareUrsnif | Ursnif has gathered information about running services. |
| T1007 System Service Discovery |
MalwareZLib | ZLib has the ability to discover and manipulate Windows services. |
| T1007 System Service Discovery |
MalwareGeminiDuke | GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup. |
| T1007 System Service Discovery |
MalwareGravityRAT | GravityRAT has a feature to list the available services on the system. |
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1007 System Service Discovery |
MalwareRainyDay | RainyDay can create and register a service for execution. |
| T1007 System Service Discovery |
MalwareGreyEnergy | GreyEnergy enumerates all Windows services. |
| T1007 System Service Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `tasklist` to gather running services on victim host. |
| T1007 System Service Discovery |
MalwareSombRAT | SombRAT can enumerate services on a victim machine. |
| T1007 System Service Discovery |
MalwareInvisiMole | InvisiMole can obtain running services on the victim. |
| T1007 System Service Discovery |
MalwareVolgmer | Volgmer queries the system to identify existing services. |
| T1007 System Service Discovery |
MalwareWINERACK | WINERACK can enumerate services. |
| T1007 System Service Discovery |
MalwareHyperBro | HyperBro can list all services and their configurations. |
| T1007 System Service Discovery |
MalwareDarkTortilla | DarkTortilla can retrieve information about a compromised system's running services. |
| T1007 System Service Discovery |
MalwareBabuk | Babuk can enumerate all services running on a compromised host. |
| T1007 System Service Discovery |
MalwareDyre | Dyre has the ability to identify running services on a compromised host. |
| T1007 System Service Discovery |
MalwareBBSRAT | BBSRAT can query service configuration information. |
| T1007 System Service Discovery |
MalwareS-Type | S-Type runs the command |
| T1007 System Service Discovery |
MalwareSykipot | Sykipot may use |
| T1007 System Service Discovery |
MalwareEpic | Epic uses the |
| T1007 System Service Discovery |
MalwareCuba | Cuba can query service status using |
| T1007 System Service Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor services. |
| T1007 System Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of the services from a system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.