ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
MalwareConficker

Conficker adds keys to the Registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and various other Registry locations.

T1112
Modify Registry
MalwareDarkTortilla

DarkTortilla has modified registry keys for persistence.

T1112
Modify Registry
MalwareROKRAT

ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host.

T1112
Modify Registry
MalwareDarkWatchman

DarkWatchman can modify Registry values to store configuration strings, keylogger, and output of components.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1112
Modify Registry
MalwareBisonal

Bisonal has deleted Registry keys to clean up its prior activity.

T1112
Modify Registry
MalwareNOOPLDR

NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`.

T1112
Modify Registry
MalwareExplosive

Explosive has a function to write itself to Registry values.

T1112
Modify Registry
MalwareRover

Rover has functionality to remove Registry Run key persistence as a cleanup procedure.

T1112
Modify Registry
MalwareClambling

Clambling can set and delete Registry keys.

T1112
Modify Registry
MalwareLockBit 3.0

LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender.

T1112
Modify Registry
MalwareHydraq

Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys.

T1112
Modify Registry
MalwareFerocious

Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms.

T1112
Modify Registry
MalwareCaterpillar WebShell

Caterpillar WebShell has a command to modify a Registry key.

T1112
Modify Registry
MalwareNetwalker

Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.

T1112
Modify Registry
MalwareChaes

Chaes can modify Registry values to stored information and establish persistence.

T1112
Modify Registry
MalwareCharmPower

CharmPower can remove persistence-related artifacts from the Registry.

T1112
Modify Registry
MalwareMuddyViper

MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence.

T1112
Modify Registry
MalwareTYPEFRAME

TYPEFRAME can install encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.

T1112
Modify Registry
MalwareEVILNUM

EVILNUM can make modifications to the Regsitry for persistence.

T1112
Modify Registry
MalwareSMOKEDHAM

SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.

T1112
Modify Registry
MalwareMori

Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values.

T1112
Modify Registry
MalwareQUADAGENT

QUADAGENT modifies an HKCU Registry key to store a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications.

T1112
Modify Registry
MalwareUroburos

Uroburos can store configuration information in the Registry including the initialization vector and AES key needed to find and decrypt other Uroburos components.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1112
Modify Registry
MalwareEmbargo

Embargo has modified and deleted Registry keys to add services, and to disable Security Solutions such as Windows Defender.

T1112
Modify Registry
MalwarePipeMon

PipeMon has modified the Registry to store its encrypted payload.

T1112
Modify Registry
MalwareKONNI

KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence.

T1112
Modify Registry
Malwaregh0st RAT

gh0st RAT has altered the InstallTime subkey.

T1112
Modify Registry
MalwareShamoon

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1112
Modify Registry
MalwareBlack Basta

Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence.

T1112
Modify Registry
MalwareCatchamas

Catchamas creates three Registry keys to establish persistence by adding a Windows Service.

T1112
Modify Registry
MalwareAttor

Attor's dispatcher can modify the Run registry key.

T1112
Modify Registry
MalwareMegaCortex

MegaCortex has added entries to the Registry for ransom contact information.

T1112
Modify Registry
MalwareStreamEx

StreamEx has the ability to modify the Registry.

T1112
Modify Registry
MalwareNightClub

NightClub can modify the Registry to set the ServiceDLL for a service created by the malware for persistence.

T1112
Modify Registry
MalwareMosquito

Mosquito can modify Registry keys under HKCU\Software\Microsoft\[dllname] to store configuration values. Mosquito also modifies Registry keys under HKCR\CLSID\...\InprocServer32 with a path to the launcher.

T1112
Modify Registry
MalwareRTM

RTM can delete all Registry entries created during its execution.

T1112
Modify Registry
MalwareBlackByte Ransomware

BlackByte Ransomware modifies the victim Registry to prevent system recovery.

T1112
Modify Registry
MalwareGrandoreiro

Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1112
Modify Registry
MalwareSibot

Sibot has modified the Registry to install a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot.

T1112
Modify Registry
MalwareTarrask

Tarrask is able to delete the Security Descriptor (`SD`) registry subkey in order to “hide” scheduled tasks.

T1112
Modify Registry
MalwareSOUNDBITE

SOUNDBITE is capable of modifying the Registry.

T1112
Modify Registry
MalwareBADCALL

BADCALL modifies the firewall Registry key SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\\List.

T1112
Modify Registry
MalwareHiddenFace

HiddenFace can store its configuration file in the Registry.

T1112
Modify Registry
MalwareHermeticWiper

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1112
Modify Registry
MalwarePysa

Pysa has modified the registry key “SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System” and added the ransom note.

T1112
Modify Registry
MalwareKapeka

Kapeka writes persistent configuration information to the victim host registry.

T1112
Modify Registry
MalwareLockBit 2.0

LockBit 2.0 can create Registry keys to bypass UAC and for persistence.

T1112
Modify Registry
MalwarePandora

Pandora can write an encrypted token to the Registry to enable processing of remote commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.