Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolPoshC2 | PoshC2 has the ability to persist on a system using WMI events. |
| T1546.004 Unix Shell Configuration Modification |
MalwareRotaJakiro | When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder. |
| T1546.004 Unix Shell Configuration Modification |
MalwareLinux Rabbit | Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files. |
| T1546.004 Unix Shell Configuration Modification |
MalwareGreen Lambert | Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells. |
| T1546.004 Unix Shell Configuration Modification |
MalwarePHASEJAM | PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands. |
| T1546.004 Unix Shell Configuration Modification |
MalwareXCSSET | Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file. |
| T1546.007 Netsh Helper DLL |
Toolnetsh | netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. |
| T1546.008 Accessibility Features |
ToolEmpire | Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe. |
| T1546.009 AppCert DLLs |
MalwarePUNCHBUGGY | PUNCHBUGGY can establish using a AppCertDLLs Registry key. |
| T1546.010 AppInit DLLs |
MalwareT9000 | If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: |
| T1546.010 AppInit DLLs |
MalwareCherry Picker | Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: |
| T1546.010 AppInit DLLs |
MalwareRamsay | Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key. |
| T1546.011 Application Shimming |
MalwareShimRat | ShimRat has installed shim databases in the |
| T1546.011 Application Shimming |
MalwareSDBbot | SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe. |
| T1546.011 Application Shimming |
MalwarePillowmint | Pillowmint has used a malicious shim database to maintain persistence. |
| T1546.012 Image File Execution Options Injection |
MalwareSDBbot | SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7. |
| T1546.012 Image File Execution Options Injection |
MalwareSUNBURST | SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process |
| T1546.015 Component Object Model Hijacking |
MalwareBBSRAT | BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList |
| T1546.015 Component Object Model Hijacking |
MalwareSVCReady | SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareFerocious | Ferocious can use COM hijacking to establish persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareKONNI | KONNI has modified ComSysApp service to load the malicious DLL payload. |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1546.015 Component Object Model Hijacking |
MalwareMosquito | Mosquito uses COM hijacking as a method of persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareComRAT | ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location |
| T1546.015 Component Object Model Hijacking |
MalwareADVSTORESHELL | Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object. |
| T1546.015 Component Object Model Hijacking |
MalwareWarzoneRAT | WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter. |
| T1546.015 Component Object Model Hijacking |
ToolSILENTTRINITY | SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`. |
| T1546.015 Component Object Model Hijacking |
ToolPcShare | PcShare has created the `HKCU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32` Registry key for persistence. |
| T1546.016 Installer Packages |
MalwareShai-Hulud | Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`. |
| T1546.016 Installer Packages |
MalwareAppleJeus | During AppleJeus's installation process, it uses `postinstall` scripts to extract a hidden plist from the application's `/Resources` folder and execute the `plist` file as a Launch Daemon with elevated permissions. |
| T1546.016 Installer Packages |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can inject malicious pre or post-install scripts within package.json for payload execution. |
| T1546.017 Udev Rules |
MalwareREPTILE | REPTILE has used udev for persistence. |
| T1546.018 Python Startup Hooks |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used .pth files to establish persistence on compromised hosts due to the Python interpreter's automatic processing of .pth files at startup. |
| T1546.018 Python Startup Hooks |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Python startup hooks to include the .pth import mechanism for execution. |
| T1547 Boot or Logon Autostart Execution |
MalwareMisdat | Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`. |
| T1547 Boot or Logon Autostart Execution |
MalwarexCaon | xCaon has added persistence via the Registry key |
| T1547 Boot or Logon Autostart Execution |
MalwareBoxCaon | BoxCaon established persistence by setting the |
| T1547 Boot or Logon Autostart Execution |
MalwareMis-Type | Mis-Type has created registry keys for persistence, including `HKCU\Software\bkfouerioyou`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{6afa8072-b2b1-31a8-b5c1-{Unique Identifier}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3BF41072-B2B1-31A8-B5C1-{Unique Identifier}`. |
| T1547 Boot or Logon Autostart Execution |
MalwareDtrack | Dtrack’s RAT makes a persistent target file with auto execution on the host start. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrickBot | TrickBot establishes persistence in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerDuke | PowerDuke achieves persistence by using various Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePikabot | Pikabot maintains persistence following system checks through the Run key in the registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGRIFFON | GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAmadey | Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNOKKI | NOKKI has established persistence by writing the payload to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvosLocker | AvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChinoxy | Chinoxy has established persistence via the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key and by loading a dropper to `(%COMMON_ STARTUP%\\eoffice.exe)`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSharpStage | SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.