ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1649
Steal or Forge Authentication Certificates
ToolAADInternals

AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices.

T1649
Steal or Forge Authentication Certificates
ToolMimikatz

Mimikatz's `CRYPTO` module can create and export various types of authentication certificates.

T1649
Steal or Forge Authentication Certificates
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments.

T1651
Cloud Administration Command
ToolPacu

Pacu can run commands on EC2 instances using AWS Systems Manager Run Command.

T1651
Cloud Administration Command
ToolAADInternals

AADInternals can execute commands on Azure virtual machines using the VM agent.

T1652
Device Driver Discovery
MalwareHOPLIGHT

HOPLIGHT can enumerate device drivers located in the registry at `HKLM\Software\WBEM\WDM`.

T1652
Device Driver Discovery
MalwareRemsec

Remsec has a plugin to detect active drivers of some security products.

T1652
Device Driver Discovery
MalwareINC Ransomware

INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.

T1653
Power Settings
MalwareLine Dancer

Line Dancer can modify the crash dump process on infected machines to skip crash dump generation and proceed directly to device reboot for both persistence and forensic evasion purposes.

T1653
Power Settings
MalwareLine Runner

Line Runner used CVE-2024-20353 to trigger victim devices to reboot, in the process unzipping and installing the Line Dancer payload.

T1654
Log Enumeration
MalwareDUSTTRAP

DUSTTRAP can identify infected system log information.

T1654
Log Enumeration
MalwareMegazord

Megazord has the ability to print the trace, debug, error, info, and warning logs.

T1654
Log Enumeration
MalwareBeaverTail

BeaverTail has identified .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1654
Log Enumeration
MalwareAkira _v2

Akira _v2 can enumerate the trace, debug, error, info, and warning logs on targeted systems.

T1654
Log Enumeration
ToolPacu

Pacu can collect CloudTrail event histories and CloudWatch logs.

T1657
Financial Theft
MalwareInvisibleFerret

InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets.

T1657
Financial Theft
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets.

T1657
Financial Theft
MalwareDarkGate

DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets.

T1657
Financial Theft
MalwareGlassWorm

GlassWorm has the ability to steal credentials for cryptocurrency wallets.

T1657
Financial Theft
MalwareEmbargo

Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom.

T1657
Financial Theft
MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

T1657
Financial Theft
MalwareCrocodilus

Crocodilus has stolen cryptocurrency wallet details from victim devices.

T1657
Financial Theft
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero.

T1659
Content Injection
MalwareDisco

Disco has achieved initial access and execution through content injection into DNS, HTTP, and SMB replies to targeted hosts that redirect them to download malicious files.

T1665
Hide Infrastructure
MalwareJumbledPath

JumbledPath can use a chain of jump hosts to communicate with compromised devices to obscure actor infrastructure.

T1665
Hide Infrastructure
MalwareUPSTYLE

UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages.

T1665
Hide Infrastructure
MalwareDarkGate

DarkGate command and control includes hard-coded domains in the malware masquerading as legitimate services such as Akamai CDN or Amazon Web Services.

T1673
Virtual Machine Discovery
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them.

T1673
Virtual Machine Discovery
MalwarePureCrypter

PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual.

T1673
Virtual Machine Discovery
MalwareVIRTUALPITA

VIRTUALPITA can target specific guest virtual machines for script execution.

T1673
Virtual Machine Discovery
MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

T1675
ESXi Administration Command
MalwareVIRTUALPITA

VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors.

T1677
Poisoned Pipeline Execution
MalwareShai-Hulud

Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`.

T1677
Poisoned Pipeline Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows.

T1677
Poisoned Pipeline Execution
MalwareCanisterWorm

CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages.

T1678
Delay Execution
MalwareBRICKSTORM

BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.

T1678
Delay Execution
MalwareTONESHELL

TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities.

T1678
Delay Execution
MalwareDynoWiper

DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot.

T1678
Delay Execution
MalwareSystemBC

SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds.

T1678
Delay Execution
MalwareRustyWater

RustyWater has generated random sleep intervals between C2 communication.

T1678
Delay Execution
MalwarePureCrypter

PureCrypter has the ability to delay for a specified number of seconds before execution.

T1678
Delay Execution
MalwareMuddyViper

MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute.

T1678
Delay Execution
MalwareFooder

Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution.

T1678
Delay Execution
MalwareGlassWorm

GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection.

T1678
Delay Execution
MalwareAshTag

AshTag can use a set sleep time to delay C2 beaconing.

T1678
Delay Execution
MalwarePHASEJAM

PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process.

T1678
Delay Execution
MalwareSPAWNCHIMERA

SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution.

T1678
Delay Execution
MalwareHIUPAN

HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available.

T1678
Delay Execution
MalwareShai-Hulud

Shai-Hulud has delayed execution of its larger payloads by forking itself into background process.

T1678
Delay Execution
MalwareQilin

Qilin has the ability to delay execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.