ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareTrojan.Karagany

Trojan.Karagany can monitor the titles of open windows to identify specific keywords.

T1010
Application Window Discovery
MalwareCatchamas

Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on.

T1010
Application Window Discovery
MalwareAttor

Attor can obtain application window titles and then determines which windows to perform Screen Capture on.

T1010
Application Window Discovery
MalwareNightClub

NightClub can use `GetForegroundWindow` to enumerate the active window.

T1010
Application Window Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on window names.

T1010
Application Window Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of enumerating application windows.

T1010
Application Window Discovery
MalwareCadelspy

Cadelspy has the ability to identify open windows on the compromised host.

T1010
Application Window Discovery
MalwareHotCroissant

HotCroissant has the ability to list the names of all open windows on the infected host.

T1010
Application Window Discovery
MalwarePoisonIvy

PoisonIvy captures window titles.

T1010
Application Window Discovery
MalwarePLEAD

PLEAD has the ability to list open windows on the compromised host.

T1010
Application Window Discovery
MalwareFunnyDream

FunnyDream has the ability to discover application windows via execution of `EnumWindows`.

T1010
Application Window Discovery
MalwareNetTraveler

NetTraveler reports window names along with keylogger information to provide application context.

T1010
Application Window Discovery
MalwarenjRAT

njRAT gathers information about opened windows during the initial infection.

T1010
Application Window Discovery
MalwareRemexi

Remexi has a command to capture active windows on the machine and retrieve window titles.

T1010
Application Window Discovery
MalwareQakBot

QakBot has the ability to enumerate windows on a compromised host.

T1010
Application Window Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`.

T1010
Application Window Discovery
ToolRemcos

Remcos can list all windows on victim systems.

T1010
Application Window Discovery
ToolQuasarRAT

APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions.

T1010
Application Window Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on open windows.

T1011.001
Exfiltration Over Bluetooth
MalwareFlame

Flame has a module named BeetleJuice that contains Bluetooth functionality that may be used in different ways, including transmitting encoded information from the infected system over the Bluetooth protocol, acting as a Bluetooth beacon, and identifying other Bluetooth devices in the vicinity.

T1012
Query Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors executed `/c cd /d c:\windows\temp\ & reg query HKEY_CURRENT_USER\Software\<username>\PuTTY\Sessions\` to detect recent PuTTY sessions, likely to further lateral movement.

T1012
Query Registry
GroupIndrik Spider

Indrik Spider has used a service account to extract copies of the `Security` Registry hive.

T1012
Query Registry
GroupBlackByte

BlackByte queried registry values to determine system language settings.

T1012
Query Registry
GroupKimsuky

Kimsuky has obtained specific Registry keys and values on a compromised host.

T1012
Query Registry
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1012
Query Registry
GroupAPT41

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

T1012
Query Registry
GroupDragonfly

Dragonfly has queried the Registry to identify victim information.

T1012
Query Registry
GroupAPT32

APT32's backdoor can query the Windows Registry to gather system information.

T1012
Query Registry
GroupGamaredon Group

Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses.

T1012
Query Registry
GroupZIRCONIUM

ZIRCONIUM has used a tool to query the Registry for proxy settings.

T1012
Query Registry
GroupAPT39

APT39 has used various strains of malware to query the Registry.

T1012
Query Registry
GroupOilRig

OilRig has used reg query “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” on a victim to query the Registry.

T1012
Query Registry
GroupTurla

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1012
Query Registry
GroupLotus Blossom

Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service.

T1012
Query Registry
GroupStealth Falcon

Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry.

T1012
Query Registry
GroupChimera

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

T1012
Query Registry
GroupFox Kitten

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.

T1012
Query Registry
GroupLazarus Group

Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key:HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt.

T1012
Query Registry
GroupDaggerfly

Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines.

T1012
Query Registry
GroupThreat Group-3390

A Threat Group-3390 tool can read and decrypt stored Registry values.

T1012
Query Registry
MalwareSynAck

SynAck enumerates Registry keys associated with event logs.

T1012
Query Registry
MalwareBumblebee

Bumblebee can check the Registry for specific keys.

T1012
Query Registry
MalwareProxysvc

Proxysvc gathers product names from the Registry key: HKLM\Software\Microsoft\Windows NT\CurrentVersion ProductName and the processor description from the Registry key HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 ProcessorNameString.

T1012
Query Registry
MalwareStuxnet

Stuxnet searches the Registry for indicators of security programs.

T1012
Query Registry
MalwarePOWRUNER

POWRUNER may query the Registry by running reg query on a victim.

T1012
Query Registry
MalwareUrsnif

Ursnif has used Reg to query the Registry for installed programs.

T1012
Query Registry
MalwarePOWERSOURCE

POWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence.

T1012
Query Registry
MalwareZeus Panda

Zeus Panda checks for the existence of a Registry key and if it contains certain values.

T1012
Query Registry
MalwareBankshot

Bankshot searches for certain Registry keys to be configured before executing the payload.

T1012
Query Registry
MalwareBrave Prince

Brave Prince gathers information about the Registry.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.