ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1569.002
Service Execution
MalwareAnchor

Anchor can create and execute services to load its payload.

T1569.002
Service Execution
MalwareBBSRAT

BBSRAT can start, stop, or delete services.

T1569.002
Service Execution
MalwareClambling

Clambling can create and start services on a compromised host.

T1569.002
Service Execution
MalwareDarkGate

DarkGate tries to elevate privileges to SYSTEM using PsExec to locally execute as a service, such as cmd /c c:\temp\PsExec.exe -accepteula -j -d -s [Target Binary].

T1569.002
Service Execution
MalwareLockBit 3.0

LockBit 3.0 can use PsExec to execute commands and payloads.

T1569.002
Service Execution
MalwareHydraq

Hydraq uses svchost.exe to execute a malicious DLL included in a new service group.

T1569.002
Service Execution
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1569.002
Service Execution
MalwareEmbargo

Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode.

T1569.002
Service Execution
Malwaregh0st RAT

gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service.

T1569.002
Service Execution
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec.

T1569.002
Service Execution
MalwareAttor

Attor's dispatcher can be executed as a service.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1569.002
Service Execution
MalwarePysa

Pysa has used PsExec to copy and execute the ransomware.

T1569.002
Service Execution
MalwarePandora

Pandora has the ability to install itself as a Windows service.

T1569.002
Service Execution
MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

T1569.002
Service Execution
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1569.002
Service Execution
MalwareIPsec Helper

IPsec Helper is run as a Windows service in victim environments.

T1569.002
Service Execution
MalwareSysUpdate

SysUpdate can manage services and processes.

T1569.002
Service Execution
MalwareZxShell

ZxShell can create a new service for execution.

T1569.002
Service Execution
MalwareWinnti for Windows

Winnti for Windows can run as a service using svchost.exe.

T1569.002
Service Execution
MalwareDEADWOOD

DEADWOOD can be executed as a service using various names, such as ScDeviceEnums.

T1569.002
Service Execution
MalwareLoudMiner

LoudMiner started the cryptomining virtual machine as a service on the infected machine.

T1569.002
Service Execution
MalwareNet Crawler

Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement.

T1569.002
Service Execution
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to start services.

T1569.002
Service Execution
MalwareHermeticWizard

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1569.002
Service Execution
ToolNet

The net start and net stop commands can be used in Net to execute or stop Windows services.

T1569.002
Service Execution
ToolImpacket

Impacket contains various modules emulating other service execution tools such as PsExec.

T1569.002
Service Execution
ToolEmpire

Empire can use PsExec to execute a payload on a remote host.

T1569.002
Service Execution
ToolPoshC2

PoshC2 contains an implementation of PsExec for remote execution.

T1569.002
Service Execution
ToolxCmd

xCmd can be used to execute binaries on remote systems by creating and starting a service.

T1569.002
Service Execution
ToolBrute Ratel C4

Brute Ratel C4 can create Windows system services for execution.

T1569.002
Service Execution
ToolWinexe

Winexe installs a service on the remote system, executes the command, then uninstalls the service.

T1569.002
Service Execution
ToolKoadic

Koadic can run a command on another machine using PsExec.

T1569.002
Service Execution
ToolPupy

Pupy uses PsExec to execute a payload or commands on a remote host.

T1569.002
Service Execution
ToolPsExec

Microsoft Sysinternals PsExec is a popular administration tool that can be used to execute binaries on remote systems using a temporary Windows service.

T1569.003
Systemctl
MalwareCanisterWorm

CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service.

T1570
Lateral Tool Transfer
MalwareStuxnet

Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network.

T1570
Lateral Tool Transfer
MalwareHavoc

Havoc has the ability to copy files from one location to another.

T1570
Lateral Tool Transfer
MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

T1570
Lateral Tool Transfer
MalwareOlympic Destroyer

Olympic Destroyer attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareSameCoin

SameCoin can copy its wiper executable to remote machines within the same Active Directory.

T1570
Lateral Tool Transfer
MalwareBlackCat

BlackCat can replicate itself across connected servers via `psexec`.

T1570
Lateral Tool Transfer
MalwareLucifer

Lucifer can use certutil for propagation on Windows hosts within intranets.

T1570
Lateral Tool Transfer
MalwareLockerGoga

LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.

T1570
Lateral Tool Transfer
MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

T1570
Lateral Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.

T1570
Lateral Tool Transfer
MalwareWannaCry

WannaCry attempts to copy itself to remote computers after gaining access via an SMB exploit.

T1570
Lateral Tool Transfer
MalwareVIRTUALPIE

VIRTUALPIE has file transfer capabilities.

T1570
Lateral Tool Transfer
MalwareShamoon

Shamoon attempts to copy itself to remote machines on the network.

T1570
Lateral Tool Transfer
MalwareBlackByte Ransomware

BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.