Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
| T1569.002 Service Execution |
MalwareBBSRAT | BBSRAT can start, stop, or delete services. |
| T1569.002 Service Execution |
MalwareClambling | Clambling can create and start services on a compromised host. |
| T1569.002 Service Execution |
MalwareDarkGate | DarkGate tries to elevate privileges to |
| T1569.002 Service Execution |
MalwareLockBit 3.0 | LockBit 3.0 can use PsExec to execute commands and payloads. |
| T1569.002 Service Execution |
MalwareHydraq | Hydraq uses svchost.exe to execute a malicious DLL included in a new service group. |
| T1569.002 Service Execution |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1569.002 Service Execution |
MalwareEmbargo | Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode. |
| T1569.002 Service Execution |
Malwaregh0st RAT | gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service. |
| T1569.002 Service Execution |
MalwareShamoon | Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec. |
| T1569.002 Service Execution |
MalwareAttor | Attor's dispatcher can be executed as a service. |
| T1569.002 Service Execution |
MalwareHermeticWiper | HermeticWiper can create system services to aid in executing the payload. |
| T1569.002 Service Execution |
MalwarePysa | |
| T1569.002 Service Execution |
MalwarePandora | Pandora has the ability to install itself as a Windows service. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| T1569.002 Service Execution |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1569.002 Service Execution |
MalwareIPsec Helper | IPsec Helper is run as a Windows service in victim environments. |
| T1569.002 Service Execution |
MalwareSysUpdate | SysUpdate can manage services and processes. |
| T1569.002 Service Execution |
MalwareZxShell | ZxShell can create a new service for execution. |
| T1569.002 Service Execution |
MalwareWinnti for Windows | Winnti for Windows can run as a service using svchost.exe. |
| T1569.002 Service Execution |
MalwareDEADWOOD | DEADWOOD can be executed as a service using various names, such as |
| T1569.002 Service Execution |
MalwareLoudMiner | LoudMiner started the cryptomining virtual machine as a service on the infected machine. |
| T1569.002 Service Execution |
MalwareNet Crawler | Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement. |
| T1569.002 Service Execution |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to start services. |
| T1569.002 Service Execution |
MalwareHermeticWizard | HermeticWizard can use `OpenRemoteServiceManager` to create a service. |
| T1569.002 Service Execution |
ToolNet | The |
| T1569.002 Service Execution |
ToolImpacket | Impacket contains various modules emulating other service execution tools such as PsExec. |
| T1569.002 Service Execution |
ToolEmpire | Empire can use PsExec to execute a payload on a remote host. |
| T1569.002 Service Execution |
ToolPoshC2 | PoshC2 contains an implementation of PsExec for remote execution. |
| T1569.002 Service Execution |
ToolxCmd | xCmd can be used to execute binaries on remote systems by creating and starting a service. |
| T1569.002 Service Execution |
ToolBrute Ratel C4 | Brute Ratel C4 can create Windows system services for execution. |
| T1569.002 Service Execution |
ToolWinexe | Winexe installs a service on the remote system, executes the command, then uninstalls the service. |
| T1569.002 Service Execution |
ToolKoadic | |
| T1569.002 Service Execution |
ToolPupy | Pupy uses PsExec to execute a payload or commands on a remote host. |
| T1569.002 Service Execution |
ToolPsExec | Microsoft Sysinternals PsExec is a popular administration tool that can be used to execute binaries on remote systems using a temporary Windows service. |
| T1569.003 Systemctl |
MalwareCanisterWorm | CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service. |
| T1570 Lateral Tool Transfer |
MalwareStuxnet | Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network. |
| T1570 Lateral Tool Transfer |
MalwareHavoc | Havoc has the ability to copy files from one location to another. |
| T1570 Lateral Tool Transfer |
MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| T1570 Lateral Tool Transfer |
MalwareOlympic Destroyer | Olympic Destroyer attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareSameCoin | SameCoin can copy its wiper executable to remote machines within the same Active Directory. |
| T1570 Lateral Tool Transfer |
MalwareBlackCat | BlackCat can replicate itself across connected servers via `psexec`. |
| T1570 Lateral Tool Transfer |
MalwareLucifer | Lucifer can use certutil for propagation on Windows hosts within intranets. |
| T1570 Lateral Tool Transfer |
MalwareLockerGoga | LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating. |
| T1570 Lateral Tool Transfer |
MalwareDustySky | DustySky searches for network drives and removable media and duplicates itself onto them. |
| T1570 Lateral Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems. |
| T1570 Lateral Tool Transfer |
MalwareWannaCry | WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit. |
| T1570 Lateral Tool Transfer |
MalwareVIRTUALPIE | VIRTUALPIE has file transfer capabilities. |
| T1570 Lateral Tool Transfer |
MalwareShamoon | Shamoon attempts to copy itself to remote machines on the network. |
| T1570 Lateral Tool Transfer |
MalwareBlackByte Ransomware | BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.