Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareFinFisher | FinFisher queries Registry values as part of its anti-sandbox checks. |
| T1012 Query Registry |
MalwareCobalt Strike | Cobalt Strike can query |
| T1012 Query Registry |
MalwareSUNBURST | SUNBURST collected the registry value |
| T1012 Query Registry |
MalwareREvil | REvil can query the Registry to get random file extensions to append to encrypted files. |
| T1012 Query Registry |
MalwareValak | Valak can use the Registry for code updates and to collect credentials. |
| T1012 Query Registry |
MalwareSamurai | Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery. |
| T1012 Query Registry |
MalwareMilan | Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1012 Query Registry |
MalwareTaidoor | Taidoor can query the Registry on compromised hosts using |
| T1012 Query Registry |
MalwareRaccoon Stealer | Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key. |
| T1012 Query Registry |
MalwareCarbon | Carbon enumerates values in the Registry. |
| T1012 Query Registry |
MalwareCardinal RAT | Cardinal RAT contains watchdog functionality that periodically ensures |
| T1012 Query Registry |
MalwareGold Dragon | Gold Dragon enumerates registry keys with the command |
| T1012 Query Registry |
MalwareCarberp | Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey. |
| T1012 Query Registry |
MalwarePillowmint | Pillowmint has used shellcode which reads code stored in the registry keys |
| T1012 Query Registry |
MalwareFunnyDream | FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string. |
| T1012 Query Registry |
MalwareCHOPSTICK | CHOPSTICK provides access to the Windows Registry, which can be used to gather information. |
| T1012 Query Registry |
MalwareFELIXROOT | FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry. |
| T1012 Query Registry |
MalwareZxShell | ZxShell can query the netsvc group value data located in the svchost group Registry key. |
| T1012 Query Registry |
MalwareBabyShark | BabyShark has executed the |
| T1012 Query Registry |
MalwarenjRAT | njRAT can read specific registry values. |
| T1012 Query Registry |
MalwareComRAT | ComRAT can check the default browser by querying |
| T1012 Query Registry |
MalwareJPIN | JPIN can enumerate Registry keys. |
| T1012 Query Registry |
MalwareQilin | Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode. |
| T1012 Query Registry |
MalwareIndustroyer | Industroyer has a data wiper component that enumerates keys in the Registry |
| T1012 Query Registry |
MalwareDownPaper | DownPaper searches and reads the value of the Windows Update Registry Run key. |
| T1012 Query Registry |
MalwareGelsemium | Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis. |
| T1012 Query Registry |
MalwareDenis | Denis queries the Registry for keys and values. |
| T1012 Query Registry |
MalwareWaterbear | Waterbear can query the Registry key |
| T1012 Query Registry |
MalwareOSInfo | OSInfo queries the registry to look for information about Terminal Services. |
| T1012 Query Registry |
MalwareDtrack | Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values. |
| T1012 Query Registry |
MalwareAzorult | Azorult can check for installed software on the system under the Registry key |
| T1012 Query Registry |
MalwareBitPaymer | BitPaymer can use the RegEnumKeyW to iterate through Registry keys. |
| T1012 Query Registry |
MalwareBACKSPACE | BACKSPACE is capable of enumerating and making modifications to an infected system's Registry. |
| T1012 Query Registry |
MalwareADVSTORESHELL | ADVSTORESHELL can enumerate registry keys. |
| T1012 Query Registry |
ToolSILENTTRINITY | SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives. |
| T1012 Query Registry |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities. |
| T1012 Query Registry |
ToolPcShare | PcShare can search the registry files of a compromised host. |
| T1012 Query Registry |
ToolRemcos | Remcos can obtain Registry data from targeted systems. |
| T1012 Query Registry |
ToolReg | Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface. |
| T1014 Rootkit |
CampaignRedPenguin | During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA. |
| T1014 Rootkit |
CampaignArcaneDoor | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
| T1014 Rootkit |
GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| T1014 Rootkit |
GroupTeamTNT | TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine. |
| T1014 Rootkit |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1014 Rootkit |
GroupUNC3886 | UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| T1014 Rootkit |
GroupAPT28 | APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax. |
| T1014 Rootkit |
GroupWinnti Group | Winnti Group used a rootkit to modify typical server functionality. |
| T1014 Rootkit |
MalwareStuxnet | Stuxnet uses a Windows rootkit to mask its binaries and other relevant files. |
| T1014 Rootkit |
MalwareMEDUSA | MEDUSA is a rootkit with command execution and credential logging capabilities. |
| T1014 Rootkit |
MalwareCOATHANGER | COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.