ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareElise

Elise executes net start after initial communication is made to the remote server.

T1007
System Service Discovery
MalwareEmbargo

Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`.

T1007
System Service Discovery
MalwareIxeshe

Ixeshe can list running services.

T1007
System Service Discovery
MalwareBlack Basta

Black Basta can check whether the service name `FAX` is present.

T1007
System Service Discovery
MalwareRATANKBA

RATANKBA uses tasklist /svc to display running tasks.

T1007
System Service Discovery
MalwareCobalt Strike

Cobalt Strike can enumerate services on compromised hosts.

T1007
System Service Discovery
MalwareSUNBURST

SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1007
System Service Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of services on the infected host.

T1007
System Service Discovery
MalwareREvil

REvil can enumerate active services.

T1007
System Service Discovery
MalwareSysUpdate

SysUpdate can collect a list of services on a victim machine.

T1007
System Service Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /svc.

T1007
System Service Discovery
MalwareLAMEHUG

LAMEHUG can gather service information on targeted systems.

T1007
System Service Discovery
MalwareLookBack

LookBack can enumerate services on the victim machine.

T1007
System Service Discovery
MalwareZxShell

ZxShell can check the services on the system.

T1007
System Service Discovery
MalwareJPIN

JPIN can list running services.

T1007
System Service Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can check if it is running as a service on a compromised host.

T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1007
System Service Discovery
MalwarejRAT

jRAT can list local services.

T1007
System Service Discovery
MalwareComnie

Comnie runs the command: net start >> %TEMP%\info.dat on a victim.

T1007
System Service Discovery
MalwareBitPaymer

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

T1007
System Service Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to enumerate services.

T1007
System Service Discovery
ToolNet

The net start command can be used in Net to find information about Windows services.

T1007
System Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can search for modifiable services that could be used for privilege escalation.

T1007
System Service Discovery
ToolTasklist

Tasklist can be used to discover services running on a system.

T1007
System Service Discovery
ToolPoshC2

PoshC2 can enumerate service and service permission information.

T1008
Fallback Channels
CampaignNight Dragon

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.

T1008
Fallback Channels
GroupAPT41

APT41 used the Steam community page as a fallback mechanism for C2.

T1008
Fallback Channels
GroupFIN7

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

T1008
Fallback Channels
GroupUNC3886

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

T1008
Fallback Channels
GroupOilRig

OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.

T1008
Fallback Channels
GroupLazarus Group

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

T1008
Fallback Channels
MalwareTrickBot

TrickBot can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers.

T1008
Fallback Channels
MalwareBumblebee

Bumblebee can use backup C2 servers if the primary server fails.

T1008
Fallback Channels
MalwareStuxnet

Stuxnet has the ability to generate new C2 domains.

T1008
Fallback Channels
MalwareExaramel for Linux

Exaramel for Linux can attempt to find a new C2 server if it receives an error.

T1008
Fallback Channels
MalwareWinMM

WinMM is usually configured with primary and backup domains for C2 communications.

T1008
Fallback Channels
MalwareRainyDay

RainyDay has the ability to switch between TCP and HTTP for C2 if one method is not working.

T1008
Fallback Channels
MalwareAppleSeed

AppleSeed can use a second channel for C2 when the primary channel is in upload mode.

T1008
Fallback Channels
MalwareTinyTurla

TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds.

T1008
Fallback Channels
MalwareSslMM

SslMM has a hard-coded primary and backup C2 string.

T1008
Fallback Channels
MalwareMachete

Machete has sent data over HTTP if FTP failed, and has also used a fallback server.

T1008
Fallback Channels
MalwareHOPLIGHT

HOPLIGHT has multiple C2 channels in place in case one fails.

T1008
Fallback Channels
MalwareInvisiMole

InvisiMole has been configured with several servers available for alternate C2 communications.

T1008
Fallback Channels
MalwareQUIETEXIT

QUIETEXIT can attempt to connect to a second hard-coded C2 if the first hard-coded C2 address fails.

T1008
Fallback Channels
MalwareRDAT

RDAT has used HTTP if DNS C2 communications were not functioning.

T1008
Fallback Channels
MalwareKazuar

Kazuar can accept multiple URLs for C2 servers.

T1008
Fallback Channels
MalwareNETEAGLE

NETEAGLE will attempt to detect if the infected host is configured to a proxy. If so, NETEAGLE will send beacons via an HTTP POST request; otherwise it will send beacons via UDP/6000.

T1008
Fallback Channels
MalwareFatDuke

FatDuke has used several C2 servers per targeted organization.

T1008
Fallback Channels
MalwareBlackEnergy

BlackEnergy has the capability to communicate over a backup channel via plus.google.com.

T1008
Fallback Channels
MalwareShimRat

ShimRat has used a secondary C2 location if the first was unavailable.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.