ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareWinnti for Windows

Winnti for Windows can add a service named wind0ws to the Registry to achieve persistence after reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1547.001
Registry Run Keys / Startup Folder
MalwareMaze

Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHIUPAN

HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareTURNEDUP

TURNEDUP is capable of writing to a Registry Run key to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareChChes

ChChes establishes persistence by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareANDROMEDA

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

T1547.001
Registry Run Keys / Startup Folder
MalwareKOCTOPUS

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeyoka Backdoor

Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareHTTPBrowser

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareOctopus

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareSTARWHALE

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareDownPaper

DownPaper uses PowerShell to add a Registry Run key in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCozyCar

One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERTON

POWERTON can install a Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBADNEWS

BADNEWS installs a registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRemexi

Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareAstaroth

Astaroth creates a startup item for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHancitor

Hancitor has added Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGelsemium

Gelsemium can set persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHelminth

Helminth establishes persistence by creating a shortcut in the Start Menu folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareComnie

Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareVasport

Vasport copies itself to disk and creates an associated run key Registry entry to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareBitPaymer

BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMivast

Mivast creates the following Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Micromedia.

T1547.001
Registry Run Keys / Startup Folder
MalwareWarzoneRAT

WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmall Sieve

Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolSILENTTRINITY

SILENTTRINITY can establish a LNK file in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolEmpire

Empire can modify the registry run keys HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolRemcos

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolMCMD

MCMD can use Registry Run Keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolKoadic

Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolPupy

Pupy adds itself to the startup folder or adds itself to the Registry key SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolQuasarRAT

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1547.002
Authentication Package
MalwareFlame

Flame can use Windows Authentication Packages for persistence.

T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1547.004
Winlogon Helper DLL
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key.

T1547.004
Winlogon Helper DLL
MalwareLockBit 3.0

LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon` Registry key.

T1547.004
Winlogon Helper DLL
MalwareGazer

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
MalwareBazar

Bazar can use Winlogon Helper DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareRevenge RAT

Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.

T1547.004
Winlogon Helper DLL
MalwareCannon

Cannon adds the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareDipsind

A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareQilin

Qilin can configure a Winlogon registry entry.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.