ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1110.003
Password Spraying
MalwareLinux Rabbit

Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server.

T1110.003
Password Spraying
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.

T1110.003
Password Spraying
ToolMailSniper

MailSniper can be used for password spraying against Exchange and Office 365.

T1110.003
Password Spraying
ToolCrackMapExec

CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password.

T1110.004
Credential Stuffing
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

T1111
Multi-Factor Authentication Interception
MalwareSykipot

Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens.

T1111
Multi-Factor Authentication Interception
MalwareSLOWPULSE

SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure.

T1111
Multi-Factor Authentication Interception
Toolevilginx2

evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA.

T1112
Modify Registry
MalwareTrickBot

TrickBot can modify registry entries.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1112
Modify Registry
MalwareSynAck

SynAck can manipulate Registry keys.

T1112
Modify Registry
MalwareExaramel for Windows

Exaramel for Windows adds the configuration to the Registry in XML format.

T1112
Modify Registry
MalwareAmadey

Amadey has overwritten registry keys for persistence.

T1112
Modify Registry
MalwareOrz

Orz can perform Registry operations.

T1112
Modify Registry
MalwareStuxnet

Stuxnet can create registry keys to load driver files.

T1112
Modify Registry
MalwareKEYMARBLE

KEYMARBLE has a command to create Registry entries for storing data under HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABE\DataPath.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1112
Modify Registry
MalwareThreatNeedle

ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1112
Modify Registry
MalwareZeus Panda

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.

T1112
Modify Registry
MalwarePrestige

Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`.

T1112
Modify Registry
MalwareBankshot

Bankshot writes data into the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pniumj.

T1112
Modify Registry
MalwarePLAINTEE

PLAINTEE uses reg add to add a Registry Run key for persistence.

T1112
Modify Registry
MalwareNETWIRE

NETWIRE can modify the Registry to store its configuration information.

T1112
Modify Registry
MalwareTinyTurla

TinyTurla can set its configuration parameters in the Registry.

T1112
Modify Registry
MalwareBOOKWORM

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1112
Modify Registry
MalwareHyperStack

HyperStack can add the name of its communication pipe to HKLM\SYSTEM\\CurrentControlSet\\Services\\lanmanserver\\parameters\NullSessionPipes.

T1112
Modify Registry
MalwareGreyEnergy

GreyEnergy modifies conditions in the Registry and adds keys.

T1112
Modify Registry
MalwareCrimson

Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number.

T1112
Modify Registry
MalwareTEARDROP

TEARDROP modified the Registry to create a Windows service for itself on a compromised host.

T1112
Modify Registry
MalwareMafalda

Mafalda can manipulate the system registry on a compromised host.

T1112
Modify Registry
MalwarePolyglotDuke

PolyglotDuke can write encrypted JSON configuration files to the Registry.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1112
Modify Registry
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution.

T1112
Modify Registry
MalwareHOPLIGHT

HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system.

T1112
Modify Registry
MalwareWastedLocker

WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.

T1112
Modify Registry
MalwareRegDuke

RegDuke can create seemingly legitimate Registry key to store its encryption key.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1112
Modify Registry
MalwareNaid

Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk.

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1112
Modify Registry
MalwareTRANSLATEXT

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.

T1112
Modify Registry
MalwareRegin

Regin appears to have functionality to modify remote Registry information.

T1112
Modify Registry
MalwareNeoichor

Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`.

T1112
Modify Registry
MalwareBlackCat

BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`

T1112
Modify Registry
MalwarePowerShower

PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process.

T1112
Modify Registry
MalwareDarkComet

DarkComet adds a Registry value for its installation routine to the Registry Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System Enable LUA=”0” and HKEY_CURRENT_USER\Software\DC3_FEXEC.

T1112
Modify Registry
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use the Windows Registry Environment key to change the `%windir%` variable to point to `c:\Windows` to enable payload execution.

T1112
Modify Registry
MalwarezwShell

zwShell can modify the Registry.

T1112
Modify Registry
MalwareDCSrv

DCSrv has created Registry keys for persistence.

T1112
Modify Registry
MalwareShimRat

ShimRat has registered two registry keys for shim databases.

T1112
Modify Registry
MalwareAvaddon

Avaddon modifies several registry keys for persistence and UAC bypass.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.