ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
GroupBlue Mockingbird

Blue Mockingbird has used Windows Registry modifications to specify a DLL payload.

T1112
Modify Registry
GroupTurla

Turla has modified Registry values to store payloads.

T1112
Modify Registry
GroupTA505

TA505 has used malware to disable Windows Defender through modification of the Registry.

T1112
Modify Registry
GroupLotus Blossom

Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry.

T1112
Modify Registry
GroupMedusa Group

Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.

T1112
Modify Registry
GroupEmber Bear

Ember Bear modifies registry values for anti-forensics and defense evasion purposes.

T1112
Modify Registry
GroupLuminousMoth

LuminousMoth has used malware that adds Registry keys for persistence.

T1112
Modify Registry
GroupAPT42

APT42 has modified Registry keys to maintain persistence.

T1112
Modify Registry
GroupEarth Lusca

Earth Lusca modified the registry using the command reg add “HKEY_CURRENT_USER\Environment” /v UserInitMprLogonScript /t REG_SZ /d “[file path]” for persistence.

T1112
Modify Registry
GroupSilence

Silence can create, delete, or modify a specified Registry key or value.

T1112
Modify Registry
GroupWizard Spider

Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest by setting the UseLogonCredential registry value to 1 in order to force credentials to be stored in clear text in memory. Wizard Spider has also modified the WDigest registry key to allow plaintext credentials to be cached in memory.

T1112
Modify Registry
GroupMagic Hound

Magic Hound has modified Registry settings for security tools.

T1112
Modify Registry
GroupThreat Group-3390

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.

T1112
Modify Registry
GroupFIN8

FIN8 has deleted Registry keys during post compromise cleanup activities.

T1112
Modify Registry
GroupAPT19

APT19 uses a Port 22 malware variant to modify several Registry keys.

T1112
Modify Registry
MalwareTrickBot

TrickBot can modify registry entries.

T1112
Modify Registry
MalwareRCSession

RCSession can write its configuration file to the Registry.

T1112
Modify Registry
MalwareSynAck

SynAck can manipulate Registry keys.

T1112
Modify Registry
MalwareExaramel for Windows

Exaramel for Windows adds the configuration to the Registry in XML format.

T1112
Modify Registry
MalwareAmadey

Amadey has overwritten registry keys for persistence.

T1112
Modify Registry
MalwareOrz

Orz can perform Registry operations.

T1112
Modify Registry
MalwareStuxnet

Stuxnet can create registry keys to load driver files.

T1112
Modify Registry
MalwareKEYMARBLE

KEYMARBLE has a command to create Registry entries for storing data under HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABE\DataPath.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1112
Modify Registry
MalwareThreatNeedle

ThreatNeedle can modify the Registry to save its configuration data as the following RC4-encrypted Registry key: `HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon`.

T1112
Modify Registry
MalwareZeus Panda

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.

T1112
Modify Registry
MalwarePrestige

Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`.

T1112
Modify Registry
MalwareBankshot

Bankshot writes data into the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pniumj.

T1112
Modify Registry
MalwarePLAINTEE

PLAINTEE uses reg add to add a Registry Run key for persistence.

T1112
Modify Registry
MalwareNETWIRE

NETWIRE can modify the Registry to store its configuration information.

T1112
Modify Registry
MalwareTinyTurla

TinyTurla can set its configuration parameters in the Registry.

T1112
Modify Registry
MalwareBOOKWORM

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1112
Modify Registry
MalwareHyperStack

HyperStack can add the name of its communication pipe to HKLM\SYSTEM\\CurrentControlSet\\Services\\lanmanserver\\parameters\NullSessionPipes.

T1112
Modify Registry
MalwareGreyEnergy

GreyEnergy modifies conditions in the Registry and adds keys.

T1112
Modify Registry
MalwareCrimson

Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number.

T1112
Modify Registry
MalwareTEARDROP

TEARDROP modified the Registry to create a Windows service for itself on a compromised host.

T1112
Modify Registry
MalwareMafalda

Mafalda can manipulate the system registry on a compromised host.

T1112
Modify Registry
MalwarePolyglotDuke

PolyglotDuke can write encrypted JSON configuration files to the Registry.

T1112
Modify Registry
MalwareShrinkLocker

ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption.

T1112
Modify Registry
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the victim Registry to allow for elevated execution.

T1112
Modify Registry
MalwareHOPLIGHT

HOPLIGHT has modified Managed Object Format (MOF) files within the Registry to run specific commands and create persistence on the system.

T1112
Modify Registry
MalwareWastedLocker

WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.

T1112
Modify Registry
MalwareRegDuke

RegDuke can create seemingly legitimate Registry key to store its encryption key.

T1112
Modify Registry
MalwareInvisiMole

InvisiMole has a command to create, set, copy, or delete a specified Registry key or value.

T1112
Modify Registry
MalwareNaid

Naid creates Registry entries that store information about a created service and point to a malicious DLL dropped to disk.

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1112
Modify Registry
MalwareTRANSLATEXT

TRANSLATEXT has modified the following registry key to install itself as the value, granting permission to install specified extensions: ` HKCU\Software\Policies\Google\Chrome\ExtensionInstallForcelist`.

T1112
Modify Registry
MalwareRegin

Regin appears to have functionality to modify remote Registry information.

T1112
Modify Registry
MalwareNeoichor

Neoichor has the ability to configure browser settings by modifying Registry entries under `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer`.

T1112
Modify Registry
MalwareBlackCat

BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.