ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1055×

65 examples

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareDOWNIISSA

DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe.

T1055
Process Injection
MalwareBBK

BBK has the ability to inject shellcode into svchost.exe.

T1055
Process Injection
MalwareWaterbear

Waterbear can inject decrypted shellcode into the LanmanServer service.

T1055
Process Injection
MalwareLizar

Lizar can migrate the loader into another process.

T1055
Process Injection
MalwareWarzoneRAT

WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation.

T1055
Process Injection
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can inject into running processes on a compromised host.

T1055
Process Injection
ToolSliver

Sliver includes multiple methods to perform process injection to migrate the framework into other, potentially privileged processes on the victim machine.

T1055
Process Injection
ToolSILENTTRINITY

SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process.

T1055
Process Injection
ToolEmpire

Empire contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolPcShare

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1055
Process Injection
ToolPoshC2

PoshC2 contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1055
Process Injection
ToolRemcos

Remcos has a command to hide itself by injecting into another process.

T1055
Process Injection
ToolDonut

Donut includes a subproject DonutTest to inject shellcode into a target process.

T1055
Process Injection
ToolIronNetInjector

IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process.

T1055
Process Injection
ToolHTRAN

HTRAN can inject into into running processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.