ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareSmoke Loader

Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmissary

Variants of Emissary have added Run Registry keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeartCrypt

HeartCrypt can set the `CurrentVersion\Run` key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareThreatNeedle

ThreatNeedle can be loaded into the Startup folder (`%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\OneDrives.lnk`) as a Shortcut file for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRansomHub

RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument.

T1547.001
Registry Run Keys / Startup Folder
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERSOURCE

POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMatryoshka

Matryoshka can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisibleFerret

InvisibleFerret has established persistence within Windows devices by creating a .bat file “queue.bat” within the Startup folder to run a Python script.

T1547.001
Registry Run Keys / Startup Folder
MalwareStrongPity

StrongPity can use the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePLAINTEE

PLAINTEE gains persistence by adding the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareNebulae

Nebulae can achieve persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTONESHELL

TONESHELL has added Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKasidet

Kasidet creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilGrab

EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.001
Registry Run Keys / Startup Folder
MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmotet

Emotet has been observed adding the downloaded payload to the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSNUGRIDE

SNUGRIDE establishes persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrimson

Crimson can add Registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTurian

Turian can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePrikormka

Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUBLOAD

PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareGootloader

Gootloader can create an autorun entry for a PowerShell script to run at reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareAuTo Stealer

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFLASHFLOOD

FLASHFLOOD achieves persistence by making an entry in the Registry's Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlawedAmmyy

FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSnip3

Snip3 can create a VBS file in startup to persist after system restarts.

T1547.001
Registry Run Keys / Startup Folder
MalwareRifdoor

Rifdoor has created a new registry entry at HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Graphics with a value of C:\ProgramData\Initech\Initech.exe /run.

T1547.001
Registry Run Keys / Startup Folder
MalwareGuLoader

GuLoader can establish persistence via the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisiMole

InvisiMole can place a lnk file in the Startup Folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCLAIMLOADER

CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareOkrum

Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRaspberry Robin

Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce
{random value name} = “rundll32 shell32 ShellExec_RunDLLA REGSVR /u /s “{dropped copy path and file name}””
.

T1547.001
Registry Run Keys / Startup Folder
MalwareMispadu

Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareRustyWater

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareIcedID

IcedID has established persistence by creating a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMarkiRAT

MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerShower

PowerShower sets up persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareKazuar

Kazuar adds a sub-key under several Registry run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNavRAT

NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETEAGLE

The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFatDuke

FatDuke has used HKLM\SOFTWARE\Microsoft\CurrentVersion\Run to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.