Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.004 Winlogon Helper DLL |
MalwareRemexi | Remexi achieves persistence using Userinit by adding the Registry key |
| T1547.005 Security Support Provider |
ToolPowerSploit | PowerSploit's |
| T1547.005 Security Support Provider |
ToolEmpire | Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's |
| T1547.005 Security Support Provider |
ToolMimikatz | The Mimikatz credential dumper contains an implementation of an SSP. |
| T1547.006 Kernel Modules and Extensions |
MalwareSkidmap | Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines. |
| T1547.006 Kernel Modules and Extensions |
MalwareREPTILE | The REPTILE rootkit is implemented as a loadable kernel module (LKM). |
| T1547.006 Kernel Modules and Extensions |
MalwareDrovorub | Drovorub can use kernel modules to establish persistence. |
| T1547.008 LSASS Driver |
MalwareWingbird | Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes. |
| T1547.008 LSASS Driver |
MalwarePasam | Pasam establishes by infecting the Security Accounts Manager (SAM) DLL to load a malicious DLL dropped to disk. |
| T1547.009 Shortcut Modification |
MalwareRedLeaves | RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. |
| T1547.009 Shortcut Modification |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.009 Shortcut Modification |
MalwareInvisiMole | InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareOkrum | Okrum can establish persistence by creating a .lnk shortcut to itself in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareMarkiRAT | MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable. |
| T1547.009 Shortcut Modification |
MalwareKazuar | Kazuar adds a .lnk file to the Windows startup folder. |
| T1547.009 Shortcut Modification |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1547.009 Shortcut Modification |
MalwareReaver | Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareS-Type | S-Type may create the file |
| T1547.009 Shortcut Modification |
MalwareSeaDuke | SeaDuke is capable of persisting via a .lnk file stored in the Startup directory. |
| T1547.009 Shortcut Modification |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe. |
| T1547.009 Shortcut Modification |
MalwareKONNI | A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareSPACESHIP | SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.009 Shortcut Modification |
MalwareMicropsia | Micropsia creates a shortcut to maintain persistence. |
| T1547.009 Shortcut Modification |
MalwareRogueRobin | RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in. |
| T1547.009 Shortcut Modification |
MalwareGrandoreiro | Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions. |
| T1547.009 Shortcut Modification |
MalwareBazar | Bazar can establish persistence by writing shortcuts to the Windows Startup folder. |
| T1547.009 Shortcut Modification |
MalwareSHIPSHAPE | SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder. |
| T1547.009 Shortcut Modification |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareFELIXROOT | FELIXROOT creates a .LNK file for persistence. |
| T1547.009 Shortcut Modification |
MalwareAstaroth | Astaroth's initial payload is a malicious .LNK file. |
| T1547.009 Shortcut Modification |
MalwareHelminth | Helminth establishes persistence by creating a shortcut. |
| T1547.009 Shortcut Modification |
MalwareComnie | Comnie establishes persistence via a .lnk file in the victim’s startup path. |
| T1547.009 Shortcut Modification |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.009 Shortcut Modification |
ToolEmpire | Empire can persist by modifying a .LNK file to include a backdoor. |
| T1547.012 Print Processors |
MalwarePipeMon | The PipeMon installer has modified the Registry key |
| T1547.012 Print Processors |
MalwareGelsemium | Gelsemium can drop itself in |
| T1547.013 XDG Autostart Entries |
MalwareRotaJakiro | When executing with user-level permissions, RotaJakiro can install persistence using a .desktop file under the `$HOME/.config/autostart/` folder. |
| T1547.013 XDG Autostart Entries |
MalwareInvisibleFerret | InvisibleFerret has established persistence within GNOME-based Linux environments by placing entries within `.desktop` that run on Startup. |
| T1547.013 XDG Autostart Entries |
MalwareNETWIRE | NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems. |
| T1547.013 XDG Autostart Entries |
MalwareFysbis | If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory. |
| T1547.013 XDG Autostart Entries |
MalwareCrossRAT | CrossRAT can use an XDG Autostart to establish persistence. |
| T1547.013 XDG Autostart Entries |
ToolPupy | Pupy can use an XDG Autostart to establish persistence. |
| T1547.014 Active Setup |
MalwarePoisonIvy | PoisonIvy creates a Registry key in the Active Setup pointing to a malicious executable. |
| T1547.015 Login Items |
MalwareNETWIRE | NETWIRE can persist via startup options for Login items. |
| T1547.015 Login Items |
MalwareGreen Lambert | Green Lambert can add Login Items to establish persistence. |
| T1547.015 Login Items |
MalwareDok | Dok uses AppleScript to install a login Item by sending Apple events to the |
| T1548 Abuse Elevation Control Mechanism |
MalwareRaspberry Robin | Raspberry Robin implements a variation of the |
| T1548.001 Setuid and Setgid |
MalwareExaramel for Linux | Exaramel for Linux can execute commands with high privileges via a specific binary with setuid functionality. |
| T1548.001 Setuid and Setgid |
MalwareKeydnap | Keydnap adds the setuid flag to a binary so it can easily elevate in the future. |
| T1548.002 Bypass User Account Control |
MalwareRCSession | RCSession can bypass UAC to escalate privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.