Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWinnti for Windows | Winnti for Windows can add a service named |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarenjRAT | njRAT has added persistence via the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMaze | Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHIUPAN | HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTURNEDUP | TURNEDUP is capable of writing to a Registry Run key to establish. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareChChes | ChChes establishes persistence by adding a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareANDROMEDA | ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKOCTOPUS | KOCTOPUS can set the AutoRun Registry key with a PowerShell command. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHeyoka Backdoor | Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHTTPBrowser | HTTPBrowser has established persistence by setting the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareOctopus | Octopus achieved persistence by placing a malicious executable in the startup directory and has added the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQilin | Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSTARWHALE | STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDownPaper | DownPaper uses PowerShell to add a Registry Run key in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCozyCar | One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br> |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAgent Tesla | Agent Tesla can add itself to the Registry as a startup program to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERTON | POWERTON can install a Registry Run key for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBADNEWS | BADNEWS installs a registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRemexi | Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAstaroth | Astaroth creates a startup item for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHancitor | Hancitor has added Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGelsemium | Gelsemium can set persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHelminth | Helminth establishes persistence by creating a shortcut in the Start Menu folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareComnie | Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVasport | Vasport copies itself to disk and creates an associated run key Registry entry to establish. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBitPaymer | BitPaymer has set the run key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMivast | Mivast creates the following Registry entry: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWarzoneRAT | WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmall Sieve | Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolSILENTTRINITY | SILENTTRINITY can establish a LNK file in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPowerSploit | PowerSploit's |
| T1547.001 Registry Run Keys / Startup Folder |
ToolEmpire | Empire can modify the registry run keys |
| T1547.001 Registry Run Keys / Startup Folder |
ToolRemcos | Remcos can add itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
ToolMCMD | MCMD can use Registry Run Keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolKoadic | Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPupy | Pupy adds itself to the startup folder or adds itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
ToolQuasarRAT | If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1547.002 Authentication Package |
MalwareFlame | Flame can use Windows Authentication Packages for persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareKeyBoy | KeyBoy issues the command |
| T1547.004 Winlogon Helper DLL |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key. |
| T1547.004 Winlogon Helper DLL |
MalwareLockBit 3.0 | LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows |
| T1547.004 Winlogon Helper DLL |
MalwareGazer | Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareBazar | Bazar can use Winlogon Helper DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareRevenge RAT | Revenge RAT creates a Registry key at |
| T1547.004 Winlogon Helper DLL |
MalwareCannon | Cannon adds the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareDipsind | A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareQilin | Qilin can configure a Winlogon registry entry. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.