ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareFinFisher

FinFisher queries Registry values as part of its anti-sandbox checks.

T1012
Query Registry
MalwareCobalt Strike

Cobalt Strike can query HKEY_CURRENT_USER\Software\Microsoft\Office\<Excel Version>\Excel\Security\AccessVBOM\ to determine if the security setting for restricting default programmatic access is enabled.

T1012
Query Registry
MalwareSUNBURST

SUNBURST collected the registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid from compromised hosts.

T1012
Query Registry
MalwareREvil

REvil can query the Registry to get random file extensions to append to encrypted files.

T1012
Query Registry
MalwareValak

Valak can use the Registry for code updates and to collect credentials.

T1012
Query Registry
MalwareSamurai

Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery.

T1012
Query Registry
MalwareMilan

Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1012
Query Registry
MalwareTaidoor

Taidoor can query the Registry on compromised hosts using RegQueryValueExA.

T1012
Query Registry
MalwareRaccoon Stealer

Raccoon Stealer queries the Windows Registry to fingerprint the infected host via the `HKLM:\SOFTWARE\Microsoft\Cryptography\MachineGuid` key.

T1012
Query Registry
MalwareCarbon

Carbon enumerates values in the Registry.

T1012
Query Registry
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that periodically ensures HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load is set to point to its executable.

T1012
Query Registry
MalwareGold Dragon

Gold Dragon enumerates registry keys with the command regkeyenum and obtains information for the Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

T1012
Query Registry
MalwareCarberp

Carberp has searched the Image File Execution Options registry key for "Debugger" within every subkey.

T1012
Query Registry
MalwarePillowmint

Pillowmint has used shellcode which reads code stored in the registry keys \REGISTRY\SOFTWARE\Microsoft\DRM using the native Windows API as well as read HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces as part of its C2.

T1012
Query Registry
MalwareFunnyDream

FunnyDream can check `Software\Microsoft\Windows\CurrentVersion\Internet Settings` to extract the `ProxyServer` string.

T1012
Query Registry
MalwareCHOPSTICK

CHOPSTICK provides access to the Windows Registry, which can be used to gather information.

T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1012
Query Registry
MalwareZxShell

ZxShell can query the netsvc group value data located in the svchost group Registry key.

T1012
Query Registry
MalwareBabyShark

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1012
Query Registry
MalwarenjRAT

njRAT can read specific registry values.

T1012
Query Registry
MalwareComRAT

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1012
Query Registry
MalwareJPIN

JPIN can enumerate Registry keys.

T1012
Query Registry
MalwareQilin

Qilin can check `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control SystemStartOptions` to determine if a machine is running in safe mode.

T1012
Query Registry
MalwareIndustroyer

Industroyer has a data wiper component that enumerates keys in the Registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services.

T1012
Query Registry
MalwareDownPaper

DownPaper searches and reads the value of the Windows Update Registry Run key.

T1012
Query Registry
MalwareGelsemium

Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis.

T1012
Query Registry
MalwareDenis

Denis queries the Registry for keys and values.

T1012
Query Registry
MalwareWaterbear

Waterbear can query the Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC\MTxOCI" to see if the value `OracleOcilib` exists.

T1012
Query Registry
MalwareOSInfo

OSInfo queries the registry to look for information about Terminal Services.

T1012
Query Registry
MalwareDtrack

Dtrack can collect the RegisteredOwner, RegisteredOrganization, and InstallDate registry values.

T1012
Query Registry
MalwareAzorult

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

T1012
Query Registry
MalwareBitPaymer

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1012
Query Registry
MalwareBACKSPACE

BACKSPACE is capable of enumerating and making modifications to an infected system's Registry.

T1012
Query Registry
MalwareADVSTORESHELL

ADVSTORESHELL can enumerate registry keys.

T1012
Query Registry
ToolSILENTTRINITY

SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.

T1012
Query Registry
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1012
Query Registry
ToolPcShare

PcShare can search the registry files of a compromised host.

T1012
Query Registry
ToolRemcos

Remcos can obtain Registry data from targeted systems.

T1012
Query Registry
ToolReg

Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface.

T1014
Rootkit
CampaignRedPenguin

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

T1014
Rootkit
CampaignArcaneDoor

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

T1014
Rootkit
GroupAPT41

APT41 deployed rootkits on Linux systems.

T1014
Rootkit
GroupTeamTNT

TeamTNT has used rootkits such as the open-source Diamorphine rootkit and their custom bots to hide cryptocurrency mining activities on the machine.

T1014
Rootkit
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1014
Rootkit
GroupUNC3886

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs.

T1014
Rootkit
GroupAPT28

APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax.

T1014
Rootkit
GroupWinnti Group

Winnti Group used a rootkit to modify typical server functionality.

T1014
Rootkit
MalwareStuxnet

Stuxnet uses a Windows rootkit to mask its binaries and other relevant files.

T1014
Rootkit
MalwareMEDUSA

MEDUSA is a rootkit with command execution and credential logging capabilities.

T1014
Rootkit
MalwareCOATHANGER

COATHANGER hooks or replaces multiple legitimate processes and other functions on victim devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.