ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1547.004
Winlogon Helper DLL
MalwareRemexi

Remexi achieves persistence using Userinit by adding the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit.

T1547.005
Security Support Provider
ToolPowerSploit

PowerSploit's Install-SSP Persistence module can be used to establish by installing a SSP DLL.

T1547.005
Security Support Provider
ToolEmpire

Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's Install-SSP and Invoke-Mimikatz to install malicious SSPs and log authentication events.

T1547.005
Security Support Provider
ToolMimikatz

The Mimikatz credential dumper contains an implementation of an SSP.

T1547.006
Kernel Modules and Extensions
MalwareSkidmap

Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.

T1547.006
Kernel Modules and Extensions
MalwareREPTILE

The REPTILE rootkit is implemented as a loadable kernel module (LKM).

T1547.006
Kernel Modules and Extensions
MalwareDrovorub

Drovorub can use kernel modules to establish persistence.

T1547.008
LSASS Driver
MalwareWingbird

Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes.

T1547.008
LSASS Driver
MalwarePasam

Pasam establishes by infecting the Security Accounts Manager (SAM) DLL to load a malicious DLL dropped to disk.

T1547.009
Shortcut Modification
MalwareRedLeaves

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence.

T1547.009
Shortcut Modification
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.009
Shortcut Modification
MalwareInvisiMole

InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence.

T1547.009
Shortcut Modification
MalwareOkrum

Okrum can establish persistence by creating a .lnk shortcut to itself in the Startup folder.

T1547.009
Shortcut Modification
MalwareMarkiRAT

MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable.

T1547.009
Shortcut Modification
MalwareKazuar

Kazuar adds a .lnk file to the Windows startup folder.

T1547.009
Shortcut Modification
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1547.009
Shortcut Modification
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.009
Shortcut Modification
MalwareS-Type

S-Type may create the file %HOMEPATH%\Start Menu\Programs\Startup\Realtek {Unique Identifier}.lnk, which points to the malicious `msdtc.exe` file already created in the `%CommonFiles%` directory.

T1547.009
Shortcut Modification
MalwareSeaDuke

SeaDuke is capable of persisting via a .lnk file stored in the Startup directory.

T1547.009
Shortcut Modification
MalwareGazer

Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe.

T1547.009
Shortcut Modification
MalwareKONNI

A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence.

T1547.009
Shortcut Modification
MalwareSPACESHIP

SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder.

T1547.009
Shortcut Modification
MalwareMicropsia

Micropsia creates a shortcut to maintain persistence.

T1547.009
Shortcut Modification
MalwareRogueRobin

RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in.

T1547.009
Shortcut Modification
MalwareGrandoreiro

Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions.

T1547.009
Shortcut Modification
MalwareBazar

Bazar can establish persistence by writing shortcuts to the Windows Startup folder.

T1547.009
Shortcut Modification
MalwareSHIPSHAPE

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.009
Shortcut Modification
MalwareTinyZBot

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1547.009
Shortcut Modification
MalwareFELIXROOT

FELIXROOT creates a .LNK file for persistence.

T1547.009
Shortcut Modification
MalwareAstaroth

Astaroth's initial payload is a malicious .LNK file.

T1547.009
Shortcut Modification
MalwareHelminth

Helminth establishes persistence by creating a shortcut.

T1547.009
Shortcut Modification
MalwareComnie

Comnie establishes persistence via a .lnk file in the victim’s startup path.

T1547.009
Shortcut Modification
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1547.009
Shortcut Modification
ToolEmpire

Empire can persist by modifying a .LNK file to include a backdoor.

T1547.012
Print Processors
MalwarePipeMon

The PipeMon installer has modified the Registry key HKLM\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Print Processors to install PipeMon as a Print Processor.

T1547.012
Print Processors
MalwareGelsemium

Gelsemium can drop itself in C:\Windows\System32\spool\prtprocs\x64\winprint.dll to be loaded automatically by the spoolsv Windows service.

T1547.013
XDG Autostart Entries
MalwareRotaJakiro

When executing with user-level permissions, RotaJakiro can install persistence using a .desktop file under the `$HOME/.config/autostart/` folder.

T1547.013
XDG Autostart Entries
MalwareInvisibleFerret

InvisibleFerret has established persistence within GNOME-based Linux environments by placing entries within `.desktop` that run on Startup.

T1547.013
XDG Autostart Entries
MalwareNETWIRE

NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems.

T1547.013
XDG Autostart Entries
MalwareFysbis

If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory.

T1547.013
XDG Autostart Entries
MalwareCrossRAT

CrossRAT can use an XDG Autostart to establish persistence.

T1547.013
XDG Autostart Entries
ToolPupy

Pupy can use an XDG Autostart to establish persistence.

T1547.014
Active Setup
MalwarePoisonIvy

PoisonIvy creates a Registry key in the Active Setup pointing to a malicious executable.

T1547.015
Login Items
MalwareNETWIRE

NETWIRE can persist via startup options for Login items.

T1547.015
Login Items
MalwareGreen Lambert

Green Lambert can add Login Items to establish persistence.

T1547.015
Login Items
MalwareDok

Dok uses AppleScript to install a login Item by sending Apple events to the System Events process.

T1548
Abuse Elevation Control Mechanism
MalwareRaspberry Robin

Raspberry Robin implements a variation of the ucmDccwCOMMethod technique abusing the Windows AutoElevate backdoor to bypass UAC while elevating privileges.

T1548.001
Setuid and Setgid
MalwareExaramel for Linux

Exaramel for Linux can execute commands with high privileges via a specific binary with setuid functionality.

T1548.001
Setuid and Setgid
MalwareKeydnap

Keydnap adds the setuid flag to a binary so it can easily elevate in the future.

T1548.002
Bypass User Account Control
MalwareRCSession

RCSession can bypass UAC to escalate privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.