ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1069.002
Domain Groups
Tooldsquery

dsquery can be used to gather information on permission groups within a domain.

T1069.002
Domain Groups
ToolBrute Ratel C4

Brute Ratel C4 can use `net group` for discovery on targeted domains.

T1069.002
Domain Groups
ToolCrackMapExec

CrackMapExec can gather the user accounts within domain groups.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

T1069.003
Cloud Groups
CampaignC0027

During C0027, Scattered Spider accessed Azure AD to download bulk lists of group members and their Active Directory attributes.

T1069.003
Cloud Groups
ToolPacu

Pacu can enumerate IAM permissions.

T1069.003
Cloud Groups
ToolAADInternals

AADInternals can enumerate Azure AD groups.

T1069.003
Cloud Groups
ToolROADTools

ROADTools can enumerate Azure AD groups.

T1069.003
Cloud Groups
GroupShinyHunters

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.

T1070
Indicator Removal
CampaignCutting Edge

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

T1070
Indicator Removal
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file.

T1070
Indicator Removal
GroupMustang Panda

Mustang Panda has deleted registry keys that store data and maintained persistence.

T1070
Indicator Removal
GroupAPT42

APT42 has cleared Chrome browser history.

T1070
Indicator Removal
GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070
Indicator Removal
GroupLazarus Group

Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked.

T1070
Indicator Removal
MalwareOrz

Orz can overwrite Registry settings to reduce its visibility on the victim.

T1070
Indicator Removal
MalwareStuxnet

Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads.

T1070
Indicator Removal
MalwareIronWind

IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems.

T1070
Indicator Removal
MalwareSardonic

Sardonic has the ability to delete created WMI objects to evade detections.

T1070
Indicator Removal
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1070
Indicator Removal
MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070
Indicator Removal
MalwareNeoichor

Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key.

T1070
Indicator Removal
MalwareBlackEnergy

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

T1070
Indicator Removal
MalwareRising Sun

Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.

T1070
Indicator Removal
MalwareFlagpro

Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections.

T1070
Indicator Removal
MalwareDarkWatchman

DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.

T1070
Indicator Removal
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script to clear file system cache memory via the ProcessIdleTasks export in advapi32.dll as an anti-analysis and anti-forensics technique.

T1070
Indicator Removal
MalwareEVILNUM

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

T1070
Indicator Removal
MalwareMetamorfo

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1070
Indicator Removal
MalwareBPFDoor

BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process.

T1070
Indicator Removal
MalwareSDBbot

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070
Indicator Removal
MalwareSibot

Sibot will delete an associated registry key if a certain server response is received.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070
Indicator Removal
MalwareSUNBURST

SUNBURST removed HTTP proxy registry values to clean up traces of execution.

T1070
Indicator Removal
MalwareIPsec Helper

IPsec Helper can delete various registry keys related to its execution and use.

T1070
Indicator Removal
MalwareFunnyDream

FunnyDream has the ability to clean traces of malware deployment.

T1070
Indicator Removal
MalwareMaze

Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection.

T1070
Indicator Removal
MalwareShadowPad

ShadowPad has deleted arbitrary Registry values.

T1070
Indicator Removal
ToolSILENTTRINITY

SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys.

T1070
Indicator Removal
ToolCSPY Downloader

CSPY Downloader has the ability to remove values it writes to the Registry.

T1070
Indicator Removal
ToolRemcos

Remcos can clean saved cookies and logins from the web browser.

T1070
Indicator Removal
ToolDonut

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

T1070.003
Clear Command History
GroupAPT41

APT41 attempted to remove evidence of some of its activity by deleting Bash histories.

T1070.003
Clear Command History
GroupmenuPass

menuPass has used Wevtutil to remove PowerShell execution logs.

T1070.003
Clear Command History
GroupTeamTNT

TeamTNT has cleared command history with history -c.

T1070.003
Clear Command History
GroupAquatic Panda

Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.

T1070.003
Clear Command History
GroupMedusa Group

Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

T1070.003
Clear Command History
GroupAPT5

APT5 has cleared the command history on targeted ESXi servers.

T1070.003
Clear Command History
GroupLazarus Group

Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility.

T1070.003
Clear Command History
GroupMagic Hound

Magic Hound has removed mailbox export requests from compromised Exchange servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.