ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1106
Native API
MalwareMis-Type

Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`.

T1106
Native API
MalwareKillDisk

KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine.

T1106
Native API
MalwareQilin

Qilin can attempt to log on to the local computer via `LogonUserW` and use `GetLogicalDrives()` and `EnumResourceW()` for discovery.

T1106
Native API
MalwareKevin

Kevin can use the `ShowWindow` API to avoid detection.

T1106
Native API
MalwareStarProxy

StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data.

T1106
Native API
MalwareBADNEWS

BADNEWS has a command to download an .exe and execute it via CreateProcess API. It can also run with ShellExecute.

T1106
Native API
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name via GetUserNameW.

T1106
Native API
MalwareQakBot

QakBot can use GetProcAddress to help delete malicious strings from memory.

T1106
Native API
MalwareDOWNIISSA

DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources.

T1106
Native API
MalwareHancitor

Hancitor has used CallWindowProc and EnumResourceTypesA to interpret and execute shellcode.

T1106
Native API
MalwareGelsemium

Gelsemium has the ability to use various Windows API functions to perform tasks.

T1106
Native API
MalwareDridex

Dridex has used the OutputDebugStringW function to avoid malware analysis as part of its anti-debugging technique.

T1106
Native API
MalwareBBK

BBK has the ability to use the CreatePipe API to add a sub-process for execution via cmd.

T1106
Native API
MalwareDenis

Denis used the IsDebuggerPresent, OutputDebugString, and SetLastError APIs to avoid debugging. Denis used GetProcAddress and LoadLibrary to dynamically resolve APIs. Denis also used the Wow64SetThreadContext API as part of a process hollowing process.

T1106
Native API
MalwareINC Ransomware

INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.

T1106
Native API
MalwareSplatCloak

SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`.

T1106
Native API
MalwareWaterbear

Waterbear can leverage API functions for execution.

T1106
Native API
MalwareLizar

Lizar has used various Windows API functions on a victim's machine.

T1106
Native API
MalwareBitPaymer

BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.

T1106
Native API
MalwareADVSTORESHELL

ADVSTORESHELL is capable of starting a process using CreateProcess.

T1106
Native API
MalwareStrifeWater

StrifeWater can use a variety of APIs for execution.

T1106
Native API
MalwareWarzoneRAT

WarzoneRAT can use a variety of API calls on a compromised host.

T1106
Native API
MalwareHermeticWizard

HermeticWizard can connect to remote shares using `WNetAddConnection2W`.

T1106
Native API
ToolBloodHound

BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data.

T1106
Native API
ToolShimRatReporter

ShimRatReporter used several Windows API functions to gather information from the infected system.

T1106
Native API
ToolSILENTTRINITY

SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`.

T1106
Native API
ToolEmpire

Empire contains a variety of enumeration modules that have an option to use API calls to carry out tasks.

T1106
Native API
ToolPcShare

PcShare has used a variety of Windows API functions.

T1106
Native API
ToolAsyncRAT

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

T1106
Native API
ToolBrute Ratel C4

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.

T1106
Native API
ToolImminent Monitor

Imminent Monitor has leveraged CreateProcessW() call to execute the debugger.

T1106
Native API
ToolDonut

Donut code modules use various API functions to load and inject code.

T1106
Native API
MalwareZeroCleare

ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory.

T1110
Brute Force
MalwareChaos

Chaos conducts brute force attacks against SSH services to gain initial access.

T1110
Brute Force
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to perform brute force attacks on a system.

T1110
Brute Force
MalwarePysa

Pysa has used brute force attempts against a central management console, as well as some Active Directory accounts.

T1110
Brute Force
MalwareKinsing

Kinsing has attempted to brute force hosts over SSH.

T1110
Brute Force
MalwareQakBot

QakBot can conduct brute force attacks to capture credentials.

T1110
Brute Force
ToolPoshC2

PoshC2 has modules for brute forcing local administrator and AD user accounts.

T1110
Brute Force
ToolCrackMapExec

CrackMapExec can brute force supplied user credentials across a network range.

T1110.001
Password Guessing
MalwarePony

Pony has used a small dictionary of common passwords against a collected list of local accounts.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1110.001
Password Guessing
MalwareP.A.S. Webshell

P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services.

T1110.001
Password Guessing
MalwareLucifer

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

T1110.001
Password Guessing
MalwareChina Chopper

China Chopper's server component can perform brute force password guessing against authentication portals.

T1110.001
Password Guessing
MalwareXbash

Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports.

T1110.001
Password Guessing
MalwareSpeakUp

SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels.

T1110.001
Password Guessing
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1110.001
Password Guessing
ToolCrackMapExec

CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network.

T1110.002
Password Cracking
MalwareNet Crawler

Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.