ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1685.005
Clear Windows Event Logs
MalwareNotPetya

NotPetya uses wevtutil to clear the Windows event logs.

T1685.005
Clear Windows Event Logs
MalwareRunningRAT

RunningRAT contains code to clear event logs.

T1685.005
Clear Windows Event Logs
MalwareMultiLayer Wiper

MultiLayer Wiper removes Windows event logs during execution.

T1685.005
Clear Windows Event Logs
MalwareLockBit 3.0

LockBit 3.0 can delete log files on targeted systems.

T1685.005
Clear Windows Event Logs
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can clear all system event logs.

T1685.005
Clear Windows Event Logs
Malwaregh0st RAT

gh0st RAT is able to wipe event logs.

T1685.005
Clear Windows Event Logs
MalwareHermeticWiper

HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

T1685.005
Clear Windows Event Logs
MalwareFinFisher

FinFisher clears the system event logs using OpenEventLog/ClearEventLog APIs .

T1685.005
Clear Windows Event Logs
MalwareZxShell

ZxShell has a command to clear system event logs.

T1685.005
Clear Windows Event Logs
MalwareMeteor

Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs.

T1685.005
Clear Windows Event Logs
MalwareKillDisk

KillDisk deletes Application, Security, Setup, and System Windows Event Logs.

T1685.005
Clear Windows Event Logs
MalwareQilin

Qilin has the ability to clear Windows Event Logs.

T1685.005
Clear Windows Event Logs
MalwareHermeticWizard

HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.

T1685.005
Clear Windows Event Logs
ToolPupy

Pupy has a module to clear event logs with PowerShell.

T1685.005
Clear Windows Event Logs
ToolWevtutil

Wevtutil can be used to clear system and security event logs from the system.

T1685.006
Clear Linux or Mac System Logs
MalwareJumbledPath

JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure.

T1685.006
Clear Linux or Mac System Logs
MalwareUPSTYLE

UPSTYLE clears error logs after reading embedded commands for execution.

T1685.006
Clear Linux or Mac System Logs
MalwareMacMa

MacMa can clear possible malware traces such as application logs.

T1685.006
Clear Linux or Mac System Logs
MalwareProton

Proton removes logs from /var/logs and /Library/logs.

T1686
Disable or Modify System Firewall
MalwareKasidet

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

T1686
Disable or Modify System Firewall
MalwareHannotog

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

T1686
Disable or Modify System Firewall
MalwarePyDCrypt

PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines.

T1686
Disable or Modify System Firewall
MalwareTHINCRUST

THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

T1686
Disable or Modify System Firewall
MalwareHOPLIGHT

HOPLIGHT has modified the firewall using netsh.

T1686
Disable or Modify System Firewall
MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

T1686
Disable or Modify System Firewall
MalwarePlugX

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.

T1686
Disable or Modify System Firewall
MalwareBPFDoor

BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port.

T1686
Disable or Modify System Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686
Disable or Modify System Firewall
MalwareNanoCore

NanoCore can modify the victim's firewall.

T1686
Disable or Modify System Firewall
MalwareZxShell

ZxShell can disable the firewall by modifying the registry key HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile.

T1686
Disable or Modify System Firewall
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1686
Disable or Modify System Firewall
MalwareBACKSPACE

The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed.

T1686
Disable or Modify System Firewall
Toolnetsh

netsh can be used to disable local firewall settings.

T1686.001
Cloud Firewall
ToolPacu

Pacu can allowlist IP addresses in AWS GuardDuty.

T1686.002
Network Device Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686.002
Network Device Firewall
MalwareCyclops Blink

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.

T1686.003
Windows Host Firewall
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the Windows firewall during execution.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

T1686.003
Windows Host Firewall
MalwareRemsec

Remsec can add or remove applications or ports on the Windows firewall or disable it entirely.

T1686.003
Windows Host Firewall
MalwareTYPEFRAME

TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections.

T1686.003
Windows Host Firewall
MalwareBADCALL

BADCALL disables the Windows firewall before binding to a port.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

T1686.003
Windows Host Firewall
MalwareHARDRAIN

HARDRAIN opens the Windows Firewall to modify incoming connections.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

T1686.003
Windows Host Firewall
MalwareH1N1

H1N1 kills and disables services for Windows Firewall.

T1688
Safe Mode Boot
MalwareAvosLocker

AvosLocker can restart a compromised machine in safe mode.

T1688
Safe Mode Boot
MalwareRansomHub

RansomHub can reboot targeted systems into Safe Mode prior to encryption.

T1688
Safe Mode Boot
MalwareLockBit 3.0

LockBit 3.0 can reboot the infected host into Safe Mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.