ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBADFLICK

BADFLICK has uploaded files from victims' machines.

T1006
Direct Volume Access
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing vssadmin in order to dump the NTDS.dit file.

T1006
Direct Volume Access
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file.

T1006
Direct Volume Access
GroupVolt Typhoon

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

T1006
Direct Volume Access
GroupScattered Spider

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

T1006
Direct Volume Access
Toolesentutl

esentutl can use the Volume Shadow Copy service to copy locked files such as `ntds.dit`.

T1007
System Service Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance.

T1007
System Service Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors.

T1007
System Service Discovery
GroupIndrik Spider

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

T1007
System Service Discovery
GroupKimsuky

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.

T1007
System Service Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: net start >> %temp%\download

T1007
System Service Discovery
GroupVolt Typhoon

Volt Typhoon has used `net start` to list running services.

T1007
System Service Discovery
GroupTeamTNT

TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them.

T1007
System Service Discovery
GroupOilRig

OilRig has used sc query on a victim to gather information about services.

T1007
System Service Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

T1007
System Service Discovery
GroupKe3chang

Ke3chang performs service discovery using net start commands.

T1007
System Service Discovery
GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1007
System Service Discovery
GroupTurla

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1007
System Service Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group discovers all running services.

T1007
System Service Discovery
GroupChimera

Chimera has used net start and net use for system service discovery.

T1007
System Service Discovery
GroupMirrorFace

MirrorFace has used Tasklist for discovery post compromise.

T1007
System Service Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1007
System Service Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1007
System Service Discovery
MalwareTrickBot

TrickBot collects a list of install programs and services on the system’s machine.

T1007
System Service Discovery
MalwareSynAck

SynAck enumerates all running services.

T1007
System Service Discovery
MalwareSardonic

Sardonic has the ability to execute the `net start` command.

T1007
System Service Discovery
MalwareEmissary

Emissary has the capability to execute the command net start to interact with services.

T1007
System Service Discovery
MalwareUrsnif

Ursnif has gathered information about running services.

T1007
System Service Discovery
MalwareZLib

ZLib has the ability to discover and manipulate Windows services.

T1007
System Service Discovery
MalwareGeminiDuke

GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup.

T1007
System Service Discovery
MalwareGravityRAT

GravityRAT has a feature to list the available services on the system.

T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1007
System Service Discovery
MalwareRainyDay

RainyDay can create and register a service for execution.

T1007
System Service Discovery
MalwareGreyEnergy

GreyEnergy enumerates all Windows services.

T1007
System Service Discovery
MalwarePUBLOAD

PUBLOAD has leveraged `tasklist` to gather running services on victim host.

T1007
System Service Discovery
MalwareSombRAT

SombRAT can enumerate services on a victim machine.

T1007
System Service Discovery
MalwareInvisiMole

InvisiMole can obtain running services on the victim.

T1007
System Service Discovery
MalwareVolgmer

Volgmer queries the system to identify existing services.

T1007
System Service Discovery
MalwareWINERACK

WINERACK can enumerate services.

T1007
System Service Discovery
MalwareHyperBro

HyperBro can list all services and their configurations.

T1007
System Service Discovery
MalwareDarkTortilla

DarkTortilla can retrieve information about a compromised system's running services.

T1007
System Service Discovery
MalwareBabuk

Babuk can enumerate all services running on a compromised host.

T1007
System Service Discovery
MalwareDyre

Dyre has the ability to identify running services on a compromised host.

T1007
System Service Discovery
MalwareBBSRAT

BBSRAT can query service configuration information.

T1007
System Service Discovery
MalwareS-Type

S-Type runs the command net start on a victim.

T1007
System Service Discovery
MalwareSykipot

Sykipot may use net start to display running services.

T1007
System Service Discovery
MalwareEpic

Epic uses the tasklist /svc command to list the services on the system.

T1007
System Service Discovery
MalwareCuba

Cuba can query service status using QueryServiceStatusEx function.

T1007
System Service Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor services.

T1007
System Service Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of the services from a system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.