ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1132.002
Non-Standard Encoding
MalwareCyclops Blink

Cyclops Blink can use a custom binary scheme to encode messages with specific commands and parameters to be executed.

T1132.002
Non-Standard Encoding
MalwareNeo-reGeorg

Neo-reGeorg can use modified Base64 encoding to obfuscate communications.

T1132.002
Non-Standard Encoding
MalwarePowGoop

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.

T1132.002
Non-Standard Encoding
MalwareShadowPad

ShadowPad has encoded data as readable Latin characters.

T1132.002
Non-Standard Encoding
MalwareLizar

Lizar has used a complex XOR operation to obfuscate C2 communications.

T1132.002
Non-Standard Encoding
MalwareBACKSPACE

Newer variants of BACKSPACE will encode C2 communications with a custom system.

T1132.002
Non-Standard Encoding
MalwareSmall Sieve

Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.

T1133
External Remote Services
MalwareLinux Rabbit

Linux Rabbit attempts to gain access to the server via SSH.

T1133
External Remote Services
MalwareMafalda

Mafalda can establish an SSH connection from a compromised host to a server.

T1133
External Remote Services
MalwareHildegard

Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment.

T1133
External Remote Services
MalwareDoki

Doki was executed through an open Docker daemon API port.

T1133
External Remote Services
MalwareKinsing

Kinsing was executed in an Ubuntu container deployed via an open Docker daemon API.

T1134
Access Token Manipulation
MalwareAppleSeed

AppleSeed can gain system level privilege by passing SeDebugPrivilege to the AdjustTokenPrivilege API.

T1134
Access Token Manipulation
MalwareSslMM

SslMM contains a feature to manipulate process privileges and tokens.

T1134
Access Token Manipulation
MalwareMafalda

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.

T1134
Access Token Manipulation
MalwareBlackCat

BlackCat has the ability modify access tokens.

T1134
Access Token Manipulation
MalwareCuba

Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.

T1134
Access Token Manipulation
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can adjust token privileges.

T1134
Access Token Manipulation
MalwareSagerunex

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1134
Access Token Manipulation
MalwareMegaCortex

MegaCortex can enable SeDebugPrivilege and adjust token privileges.

T1134
Access Token Manipulation
MalwareRyuk

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1134
Access Token Manipulation
MalwareSUNSPOT

SUNSPOT modified its security token to grants itself debugging privileges by adding SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareKillDisk

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.

T1134
Access Token Manipulation
MalwareQilin

Qilin can use an embedded Mimikatz module for token manipulation.

T1134
Access Token Manipulation
MalwareGelsemium

Gelsemium can use token manipulation to bypass UAC on Windows7 systems.

T1134
Access Token Manipulation
ToolSliver

Sliver has the ability to manipulate user tokens on targeted Windows systems.

T1134
Access Token Manipulation
ToolPowerSploit

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

T1134
Access Token Manipulation
ToolEmpire

Empire can use PowerSploit's Invoke-TokenManipulation to manipulate access tokens.

T1134
Access Token Manipulation
ToolPoshC2

PoshC2 can use Invoke-TokenManipulation for manipulating tokens.

T1134
Access Token Manipulation
MalwareDuqu

Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges.

T1134.001
Token Impersonation/Theft
MalwareStuxnet

Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager.

T1134.001
Token Impersonation/Theft
MalwareHavoc

Havoc has a module capable of token impersonation.

T1134.001
Token Impersonation/Theft
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

T1134.001
Token Impersonation/Theft
MalwareBADHATCH

BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token.

T1134.001
Token Impersonation/Theft
MalwareOkrum

Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API.

T1134.001
Token Impersonation/Theft
MalwareSiloscape

Siloscape impersonates the main thread of CExecSvc.exe by calling NtImpersonateThread.

T1134.001
Token Impersonation/Theft
MalwareFooder

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

T1134.001
Token Impersonation/Theft
MalwareLP-Notes

LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API.

T1134.001
Token Impersonation/Theft
MalwareShamoon

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

T1134.001
Token Impersonation/Theft
MalwareTarrask

Tarrask leverages token theft to obtain `lsass.exe` security permissions.

T1134.001
Token Impersonation/Theft
MalwareFinFisher

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

T1134.001
Token Impersonation/Theft
MalwareREvil

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.

T1134.001
Token Impersonation/Theft
MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

T1134.001
Token Impersonation/Theft
ToolSILENTTRINITY

SILENTTRINITY can find a process owned by a specific user and impersonate the associated token.

T1134.001
Token Impersonation/Theft
ToolPupy

Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate.

T1134.002
Create Process with Token
MalwareBankshot

Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user.

T1134.002
Create Process with Token
MalwareTONESHELL

TONESHELL included functionality to create sub-processes with a specific user’s token.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.