ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1688
Safe Mode Boot
MalwareEmbargo

Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode.

T1688
Safe Mode Boot
MalwareBlack Basta

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.

T1688
Safe Mode Boot
MalwareREvil

REvil can force a reboot in safe mode with networking.

T1688
Safe Mode Boot
MalwareQilin

Qilin can reboot targeted systems in safe mode to avoid detection.

T1689
Downgrade Attack
MalwareBlackByte Ransomware

BlackByte Ransomware enables SMBv1 during execution.

T1689
Downgrade Attack
ToolSILENTTRINITY

SILENTTRINITY can downgrade NTLM to capture NTLM hashes.

T1690
Prevent Command History Logging
MalwareBRICKSTORM

BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input.

T1690
Prevent Command History Logging
MalwareLine Dancer

Line Dancer can disable syslog on compromised devices.

T1690
Prevent Command History Logging
MalwareBPFDoor

BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

T1690
Prevent Command History Logging
MalwareVIRTUALPITA

VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service.

T1690
Prevent Command History Logging
ToolSILENTTRINITY

SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.