Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.003 Windows Service |
MalwareKwampirs | Kwampirs creates a new service named WmiApSrvEx to establish persistence. |
| T1543.003 Windows Service |
MalwareNerex | Nerex creates a Registry subkey that registers a new service. |
| T1543.003 Windows Service |
MalwareInnaputRAT | Some InnaputRAT variants create a new Windows service to establish persistence. |
| T1543.003 Windows Service |
MalwareZxShell | ZxShell can create a new service using the service parser function ProcessScCommand. |
| T1543.003 Windows Service |
MalwareWinnti for Windows | Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence. |
| T1543.003 Windows Service |
MalwareAppleJeus | AppleJeus can install itself as a service. |
| T1543.003 Windows Service |
MalwareSTARWHALE | STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`. |
| T1543.003 Windows Service |
MalwareIndustroyer | Industroyer can use an arbitrary system service to load at system boot for persistence and replaces the ImagePath registry value of a Windows service with a new backdoor binary. |
| T1543.003 Windows Service |
MalwareCozyCar | One persistence mechanism used by CozyCar is to register itself as a Windows service. |
| T1543.003 Windows Service |
MalwareQakBot | QakBot can remotely create a temporary service on a target host. |
| T1543.003 Windows Service |
MalwareGelsemium | Gelsemium can drop itself in `C:\Windows\System32\spool\prtprocs\x64\winprint.dll` as an alternative Print Processor to be loaded automatically when the spoolsv Windows service starts. |
| T1543.003 Windows Service |
MalwareDtrack | Dtrack can add a service called WBService to establish persistence. |
| T1543.003 Windows Service |
MalwareLoudMiner | LoudMiner can automatically launch a Linux virtual machine as a service at startup if the AutoStart option is enabled in the VBoxVmService configuration file. |
| T1543.003 Windows Service |
MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
| T1543.003 Windows Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence. |
| T1543.003 Windows Service |
MalwareFALLCHILL | FALLCHILL has been installed as a Windows service. |
| T1543.003 Windows Service |
ToolSILENTTRINITY | SILENTTRINITY can establish persistence by creating a new service. |
| T1543.003 Windows Service |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs. |
| T1543.003 Windows Service |
ToolEmpire | Empire can utilize built-in modules to modify service binaries and restore them to their original state. |
| T1543.003 Windows Service |
ToolRemcos | Remcos can terminate, suspend, and resume a process by PID. |
| T1543.003 Windows Service |
ToolPsExec | PsExec can leverage Windows services to escalate privileges from administrator to SYSTEM with the |
| T1543.003 Windows Service |
MalwareDuqu | Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key. |
| T1543.004 Launch Daemon |
MalwareCOATHANGER | COATHANGER will create a daemon for timed check-ins with command and control infrastructure. |
| T1543.004 Launch Daemon |
MalwareDacls | Dacls can establish persistence via a Launch Daemon. |
| T1543.004 Launch Daemon |
MalwareREPTILE | The REPTILE launcher can daemonize a process. |
| T1543.004 Launch Daemon |
MalwareGreen Lambert | Green Lambert can add a plist file in the `Library/LaunchDaemons` to establish persistence. |
| T1543.004 Launch Daemon |
MalwareThiefQuest | When running with root privileges after a Launch Agent is installed, ThiefQuest installs a plist file to the |
| T1543.004 Launch Daemon |
MalwareBundlore | Bundlore can persist via a LaunchDaemon. |
| T1543.004 Launch Daemon |
MalwareOSX_OCEANLOTUS.D | If running with |
| T1543.004 Launch Daemon |
MalwareXCSSET | XCSSET uses the ssh launchdaemon to elevate privileges, bypass system controls, and enable remote access to the victim. |
| T1543.004 Launch Daemon |
MalwareAppleJeus | AppleJeus has placed a plist file within the |
| T1543.004 Launch Daemon |
MalwareLoudMiner | LoudMiner adds plist files with the naming format |
| T1546 Event Triggered Execution |
MalwareUPSTYLE | UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run. |
| T1546 Event Triggered Execution |
MalwareXCSSET | XCSSET's `dfhsebxzod` module searches for `.xcodeproj` directories within the user’s home folder and subdirectories. For each match, it locates the corresponding `project.pbxproj` file and embeds an encoded payload into a build rule, target configuration, or project setting. The payload is later executed during the build process. |
| T1546 Event Triggered Execution |
ToolPacu | Pacu can set up S3 bucket notifications to trigger a malicious Lambda function when a CloudFormation template is uploaded to the bucket. It can also create Lambda functions that trigger upon the creation of users, roles, and groups. |
| T1546 Event Triggered Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions. |
| T1546.001 Change Default File Association |
ToolSILENTTRINITY | SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process. |
| T1546.002 Screensaver |
MalwareGazer | Gazer can establish persistence through the system screensaver by configuring it to execute the malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareSardonic | Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
Malwareadbupd | adbupd can use a WMI script to achieve persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareBADHATCH | BADHATCH can use WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareHOPLIGHT | HOPLIGHT can use WMI event subscriptions to create persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareRegDuke | RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOSHSPY | POSHSPY uses a WMI event subscription to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareSeaDuke | SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareTrailBlazer | TrailBlazer has the ability to use WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwaremetaMain | metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareKevin | Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOWERTON | POWERTON can use WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolSILENTTRINITY | SILENTTRINITY can create a WMI Event to execute a payload for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.