ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1112
Modify Registry
ToolRemcos

Remcos has full control of the Registry, including the ability to modify it.

T1112
Modify Registry
ToolCrackMapExec

CrackMapExec can create a registry key using wdigest.

T1112
Modify Registry
ToolReg

Reg may be used to interact with and modify the Windows Registry of a local or remote system at the command-line interface.

T1112
Modify Registry
ToolQuasarRAT

QuasarRAT has a command to edit the Registry on the victim’s machine.

T1113
Screen Capture
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using nircmd console through the command nircmd.exe “savescreenshot C:\Windows\Temp\imagetmp.png.

T1113
Screen Capture
GroupKimsuky

Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware.

T1113
Screen Capture
GroupVolt Typhoon

Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

T1113
Screen Capture
GroupMuddyWater

MuddyWater has used malware that can capture screenshots of the victim’s machine.

T1113
Screen Capture
GroupGamaredon Group

Gamaredon Group's malware can take screenshots of the compromised computer every minute.

T1113
Screen Capture
GroupFIN7

FIN7 captured screenshots and desktop video recordings.

T1113
Screen Capture
GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

T1113
Screen Capture
GroupOilRig

OilRig has a tool called CANDYKING to capture a screenshot of user's desktop.

T1113
Screen Capture
GroupMoustachedBouncer

MoustachedBouncer has used plugins to take screenshots on targeted systems.

T1113
Screen Capture
GroupGroup5

Malware used by Group5 is capable of watching the victim's screen.

T1113
Screen Capture
GroupWinter Vivern

Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines.

T1113
Screen Capture
GroupDark Caracal

Dark Caracal took screenshots using their Windows malware.

T1113
Screen Capture
GroupBRONZE BUTLER

BRONZE BUTLER has used a tool to capture screenshots.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1113
Screen Capture
GroupAPT42

APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots.

T1113
Screen Capture
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines.

T1113
Screen Capture
GroupSilence

Silence can capture victim screen activity.

T1113
Screen Capture
GroupVOID MANTICORE

VOID MANTICORE has captured screen content during an active Zoom session.

T1113
Screen Capture
GroupMagic Hound

Magic Hound malware can take a screenshot and upload the file to its C2 server.

T1113
Screen Capture
MalwareRCSession

RCSession can capture screenshots from a compromised host.

T1113
Screen Capture
MalwareQuietSieve

QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`.

T1113
Screen Capture
MalwareGRIFFON

GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system.

T1113
Screen Capture
Malwareyty

yty collects screenshots of the victim machine.

T1113
Screen Capture
MalwareDOGCALL

DOGCALL is capable of capturing screenshots of the victim's machine.

T1113
Screen Capture
MalwarePOWRUNER

POWRUNER can capture a screenshot from a victim.

T1113
Screen Capture
MalwareSharpStage

SharpStage has the ability to capture the victim's screen.

T1113
Screen Capture
MalwareHALFBAKED

HALFBAKED can obtain screenshots from the victim.

T1113
Screen Capture
MalwareKEYMARBLE

KEYMARBLE can capture screenshots of the victim’s machine.

T1113
Screen Capture
MalwareUrsnif

Ursnif has used hooked APIs to take screenshots.

T1113
Screen Capture
MalwareZLib

ZLib has the ability to obtain screenshots of the compromised system.

T1113
Screen Capture
MalwareRedLeaves

RedLeaves can capture screenshots.

T1113
Screen Capture
MalwareZeus Panda

Zeus Panda can take screenshots of the victim’s machine.

T1113
Screen Capture
MalwareHavoc

Havoc can capture screenshots.

T1113
Screen Capture
MalwareMatryoshka

Matryoshka is capable of performing screen captures.

T1113
Screen Capture
MalwareJanicab

Janicab captured screenshots and sent them out to a C2 server.

T1113
Screen Capture
MalwareTONESHELL

TONESHELL has conducted screen capturing.

T1113
Screen Capture
MalwareKasidet

Kasidet has the ability to initiate keylogging and screen captures.

T1113
Screen Capture
MalwareRainyDay

RainyDay has the ability to capture screenshots.

T1113
Screen Capture
MalwareAppleSeed

AppleSeed can take screenshots on a compromised host by calling a series of APIs.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1113
Screen Capture
MalwareCosmicDuke

CosmicDuke takes periodic screenshots and exfiltrates them.

T1113
Screen Capture
MalwareEvilGrab

EvilGrab has the capability to capture screenshots.

T1113
Screen Capture
MalwareAria-body

Aria-body has the ability to capture screenshots on compromised hosts.

T1113
Screen Capture
MalwareCrimson

Crimson contains a command to perform screen captures.

T1113
Screen Capture
MalwareDUSTTRAP

DUSTTRAP can capture screenshots.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.