Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupThreat Group-3390 | Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT33 | APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN10 | FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN13 | FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT19 | An APT19 HTTP malware variant establishes persistence by setting the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamPCP | TeamPCP has dropped malware into the Windows Startup folder to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.