ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

57 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupMagic Hound

Magic Hound malware has used Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupThreat Group-3390

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN10

FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN13

FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT19

An APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Windows Debug Tools-%LOCALAPPDATA%\.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamPCP

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.