ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1134
Access Token Manipulation
MalwareMafalda

Mafalda can use `AdjustTokenPrivileges()` to elevate privileges.

T1134
Access Token Manipulation
MalwareBlackCat

BlackCat has the ability modify access tokens.

T1134
Access Token Manipulation
MalwareCuba

Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.

T1134
Access Token Manipulation
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can adjust token privileges.

T1134
Access Token Manipulation
MalwareSagerunex

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1134
Access Token Manipulation
MalwareMegaCortex

MegaCortex can enable SeDebugPrivilege and adjust token privileges.

T1134
Access Token Manipulation
MalwareRyuk

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1134
Access Token Manipulation
MalwareSUNSPOT

SUNSPOT modified its security token to grants itself debugging privileges by adding SeDebugPrivilege.

T1134
Access Token Manipulation
MalwareKillDisk

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.

T1134
Access Token Manipulation
MalwareQilin

Qilin can use an embedded Mimikatz module for token manipulation.

T1134
Access Token Manipulation
MalwareGelsemium

Gelsemium can use token manipulation to bypass UAC on Windows7 systems.

T1134
Access Token Manipulation
ToolSliver

Sliver has the ability to manipulate user tokens on targeted Windows systems.

T1134
Access Token Manipulation
ToolPowerSploit

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

T1134
Access Token Manipulation
ToolEmpire

Empire can use PowerSploit's Invoke-TokenManipulation to manipulate access tokens.

T1134
Access Token Manipulation
ToolPoshC2

PoshC2 can use Invoke-TokenManipulation for manipulating tokens.

T1134
Access Token Manipulation
MalwareDuqu

Duqu examines running system processes for tokens that have specific system privileges. If it finds one, it will copy the token and store it for later use. Eventually it will start new processes with the stored token attached. It can also steal tokens to acquire administrative privileges.

T1134.001
Token Impersonation/Theft
CampaignHomeLand Justice

During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`.

T1134.001
Token Impersonation/Theft
GroupAPT28

APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation.

T1134.001
Token Impersonation/Theft
GroupFIN8

FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token.

T1134.001
Token Impersonation/Theft
MalwareStuxnet

Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager.

T1134.001
Token Impersonation/Theft
MalwareHavoc

Havoc has a module capable of token impersonation.

T1134.001
Token Impersonation/Theft
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

T1134.001
Token Impersonation/Theft
MalwareBADHATCH

BADHATCH can impersonate a `lsass.exe` or `vmtoolsd.exe` token.

T1134.001
Token Impersonation/Theft
MalwareOkrum

Okrum can impersonate a logged-on user's security context using a call to the ImpersonateLoggedOnUser API.

T1134.001
Token Impersonation/Theft
MalwareSiloscape

Siloscape impersonates the main thread of CExecSvc.exe by calling NtImpersonateThread.

T1134.001
Token Impersonation/Theft
MalwareFooder

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

T1134.001
Token Impersonation/Theft
MalwareLP-Notes

LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API.

T1134.001
Token Impersonation/Theft
MalwareShamoon

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

T1134.001
Token Impersonation/Theft
MalwareTarrask

Tarrask leverages token theft to obtain `lsass.exe` security permissions.

T1134.001
Token Impersonation/Theft
MalwareFinFisher

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

T1134.001
Token Impersonation/Theft
MalwareCobalt Strike

Cobalt Strike can steal access tokens from exiting processes.

T1134.001
Token Impersonation/Theft
MalwareREvil

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.

T1134.001
Token Impersonation/Theft
MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

T1134.001
Token Impersonation/Theft
ToolSILENTTRINITY

SILENTTRINITY can find a process owned by a specific user and impersonate the associated token.

T1134.001
Token Impersonation/Theft
ToolPupy

Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate.

T1134.002
Create Process with Token
GroupTurla

Turla RPC backdoors can impersonate or steal process tokens before executing commands.

T1134.002
Create Process with Token
GroupLazarus Group

Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call CreateProcessAsUserA under that user's context.

T1134.002
Create Process with Token
MalwareBankshot

Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user.

T1134.002
Create Process with Token
MalwareTONESHELL

TONESHELL included functionality to create sub-processes with a specific user’s token.

T1134.002
Create Process with Token
MalwareAria-body

Aria-body has the ability to execute a process using runas.

T1134.002
Create Process with Token
MalwareWhisperGate

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.

T1134.002
Create Process with Token
MalwarePipeMon

PipeMon can attempt to gain administrative privileges using token impersonation.

T1134.002
Create Process with Token
MalwareKONNI

KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.

T1134.002
Create Process with Token
MalwareREvil

REvil can launch an instance of itself with administrative rights using runas.

T1134.002
Create Process with Token
MalwareZxShell

ZxShell has a command called RunAs, which creates a new process as another user or process context.

T1134.002
Create Process with Token
MalwareAzorult

Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges.

T1134.002
Create Process with Token
ToolEmpire

Empire can use Invoke-RunAs to make tokens.

T1134.002
Create Process with Token
ToolPoshC2

PoshC2 can use Invoke-RunAs to make tokens.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.