ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1543.003
Windows Service
MalwareKwampirs

Kwampirs creates a new service named WmiApSrvEx to establish persistence.

T1543.003
Windows Service
MalwareNerex

Nerex creates a Registry subkey that registers a new service.

T1543.003
Windows Service
MalwareInnaputRAT

Some InnaputRAT variants create a new Windows service to establish persistence.

T1543.003
Windows Service
MalwareZxShell

ZxShell can create a new service using the service parser function ProcessScCommand.

T1543.003
Windows Service
MalwareWinnti for Windows

Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence.

T1543.003
Windows Service
MalwareAppleJeus

AppleJeus can install itself as a service.

T1543.003
Windows Service
MalwareSTARWHALE

STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`.

T1543.003
Windows Service
MalwareIndustroyer

Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary.

T1543.003
Windows Service
MalwareCozyCar

One persistence mechanism used by CozyCar is to register itself as a Windows service.

T1543.003
Windows Service
MalwareQakBot

QakBot can remotely create a temporary service on a target host.

T1543.003
Windows Service
MalwareGelsemium

Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts.

T1543.003
Windows Service
MalwareDtrack

Dtrack can add a service called WBService to establish persistence.

T1543.003
Windows Service
MalwareLoudMiner

LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file.

T1543.003
Windows Service
MalwareBitPaymer

BitPaymer has attempted to install itself as a service to maintain persistence.

T1543.003
Windows Service
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence.

T1543.003
Windows Service
MalwareFALLCHILL

FALLCHILL has been installed as a Windows service.

T1543.003
Windows Service
ToolSILENTTRINITY

SILENTTRINITY can establish persistence by creating a new service.

T1543.003
Windows Service
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs.

T1543.003
Windows Service
ToolEmpire

Empire can utilize built-in modules to modify service binaries and restore them to their original state.

T1543.003
Windows Service
ToolRemcos

Remcos can terminate, suspend, and resume a process by PID.

T1543.003
Windows Service
ToolPsExec

PsExec can leverage Windows services to escalate privileges from administrator to SYSTEM with the -s argument.

T1543.003
Windows Service
MalwareDuqu

Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key.

T1543.004
Launch Daemon
MalwareCOATHANGER

COATHANGER will create a daemon for timed check-ins with command and control infrastructure.

T1543.004
Launch Daemon
MalwareDacls

Dacls can establish persistence via a Launch Daemon.

T1543.004
Launch Daemon
MalwareREPTILE

The REPTILE launcher can daemonize a process.

T1543.004
Launch Daemon
MalwareGreen Lambert

Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence.

T1543.004
Launch Daemon
MalwareThiefQuest

When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the /Library/LaunchDaemons/ folder with the RunAtLoad key set to true establishing persistence as a Launch Daemon.

T1543.004
Launch Daemon
MalwareBundlore

Bundlore can persist via a LaunchDaemon.

T1543.004
Launch Daemon
MalwareOSX_OCEANLOTUS.D

If running with root permissions, OSX_OCEANLOTUS.D can create a persistence file in the folder /Library/LaunchDaemons.

T1543.004
Launch Daemon
MalwareXCSSET

XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim.

T1543.004
Launch Daemon
MalwareAppleJeus

AppleJeus has placed a plist file within the LaunchDaemons folder and launched it manually.

T1543.004
Launch Daemon
MalwareLoudMiner

LoudMiner adds plist files with the naming format com.[random_name].plist in the /Library/LaunchDaemons folder with the RunAtLoad and KeepAlive keys set to true.

T1546
Event Triggered Execution
MalwareUPSTYLE

UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run.

T1546
Event Triggered Execution
MalwareXCSSET

XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process.

T1546
Event Triggered Execution
ToolPacu

Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups.

T1546
Event Triggered Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions.

T1546.001
Change Default File Association
ToolSILENTTRINITY

SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process.

T1546.002
Screensaver
MalwareGazer

Gazer can establish persistence through the system screensaver by configuring it to execute the malware.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSardonic

Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence.

T1546.003
Windows Management Instrumentation Event Subscription
Malwareadbupd

adbupd can use a WMI script to achieve persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareBADHATCH

BADHATCH can use WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareHOPLIGHT

HOPLIGHT can use WMI event subscriptions to create persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareRegDuke

RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOSHSPY

POSHSPY uses a WMI event subscription to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSeaDuke

SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareTrailBlazer

TrailBlazer has the ability to use WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwaremetaMain

metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareKevin

Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOWERTON

POWERTON can use WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
ToolSILENTTRINITY

SILENTTRINITY can create a WMI Event to execute a payload for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.