ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1012
Query Registry
MalwareSUNBURST

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1012
Query Registry
MalwareREvil

REvil can query the Registry to get random file extensions to append to encrypted files.

T1012
Query Registry
MalwareValak

Valak can use the Registry for code updates and to collect credentials.

T1012
Query Registry
MalwareSamurai

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1012
Query Registry
MalwareMilan

Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1012
Query Registry
MalwareTaidoor

Taidoor can query the Registry on compromised hosts using RegQueryValueExA.

T1012
Query Registry
MalwareRaccoon Stealer

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1012
Query Registry
MalwareCarbon

Carbon enumerates values in the Registry.

T1012
Query Registry
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that periodically ensures HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load is set to point to its executable.

T1012
Query Registry
MalwareGold Dragon

Gold Dragon enumerates registry keys with the command regkeyenum and obtains information for the Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1012
Query Registry
MalwareCarberp

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1012
Query Registry
MalwarePillowmint

Pillowmint has used shellcode which reads code stored in the registry keys \REGISTRY\SOFTWARE\Microsoft\DRM using the native Windows API as well as read HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces as part of its C2.

T1012
Query Registry
MalwareFunnyDream

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1012
Query Registry
MalwareCHOPSTICK

CHOPSTICK provides access to the Windows Registry, which can be used to gather information.

T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1012
Query Registry
MalwareZxShell

ZxShell can query the netsvc group value data located in the svchost group Registry key.

T1012
Query Registry
MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1012
Query Registry
MalwarenjRAT

njRAT can read specific registry values.

T1012
Query Registry
MalwareComRAT

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1012
Query Registry
MalwareJPIN

JPIN can enumerate Registry keys.

T1012
Query Registry
MalwareQilin

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1012
Query Registry
MalwareIndustroyer

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1012
Query Registry
MalwareDownPaper

DownPaper searches and reads the value of the Windows Update Registry Run key.

T1012
Query Registry
MalwareGelsemium

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1012
Query Registry
MalwareDenis

Denis queries the Registry for keys and values.

T1012
Query Registry
MalwareWaterbear

Waterbear can query the Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI" to see if the value `OracleOcilib` exists.

T1012
Query Registry
MalwareOSInfo

OSInfo queries the registry to look for information about Terminal Services.

T1012
Query Registry
MalwareDtrack

Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values.

T1012
Query Registry
MalwareAzorult

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

T1012
Query Registry
MalwareBitPaymer

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1012
Query Registry
MalwareBACKSPACE

BACKSPACE is capable of enumerating and making modifications to an infected system's Registry.

T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1012
Query Registry
ToolSILENTTRINITY

SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.

T1012
Query Registry
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1012
Query Registry
ToolPcShare

PcShare can search the registry files of a compromised host.

T1012
Query Registry
ToolRemcos

Remcos can obtain Registry data from targeted systems.

T1012
Query Registry
ToolReg

Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface.

T1014
Rootkit
MalwareStuxnet

Stuxnet uses a Windows rootkit to mask its binaries and other relevant files.

T1014
Rootkit
MalwareMEDUSA

MEDUSA is a rootkit with command execution and credential logging capabilities.

T1014
Rootkit
MalwareCOATHANGER

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

T1014
Rootkit
MalwareUmbreon

Umbreon hides from defenders by hooking libc function calls, hiding artifacts that would reveal its presence, such as the user account it creates to provide access and undermining strace, a tool often used to identify malware.

T1014
Rootkit
MalwareHildegard

Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64().

T1014
Rootkit
MalwareHacking Team UEFI Rootkit

Hacking Team UEFI Rootkit is a UEFI BIOS rootkit developed by the company Hacking Team to persist remote access software on some targeted systems.

T1014
Rootkit
MalwareSkidmap

Skidmap is a kernel-mode rootkit that has the ability to hook system calls to hide specific files and fake network and CPU-related statistics to make the CPU load of the infected machine always appear low.

T1014
Rootkit
MalwareLine Dancer

Line Dancer can hook both the crash dump process and the Autehntication, Authorization, and Accounting (AAA) functions on compromised machines to evade forensic analysis and authentication mechanisms.

T1014
Rootkit
MalwareREPTILE

REPTILE has the ability to hook kernel functions and modify functions data to achieve rootkit functionality such as hiding processes and network connections.

T1014
Rootkit
MalwareZeroaccess

Zeroaccess is a kernel-mode rootkit.

T1014
Rootkit
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a rootkit on a system.

T1014
Rootkit
MalwareUroburos

Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.