ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1222.001
Windows Permissions
GroupStorm-1811

Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.

T1222.001
Windows Permissions
GroupWizard Spider

Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.

T1222.001
Windows Permissions
MalwareWastedLocker

WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.

T1222.001
Windows Permissions
MalwareBlackCat

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

T1222.001
Windows Permissions
MalwareWannaCry

WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.

T1222.001
Windows Permissions
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

T1222.001
Windows Permissions
MalwareGrandoreiro

Grandoreiro can modify the binary ACL to prevent security tools from running.

T1222.001
Windows Permissions
MalwareRyuk

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

T1222.001
Windows Permissions
MalwareCaddyWiper

CaddyWiper can modify ACL entries to take ownership of files.

T1222.001
Windows Permissions
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1222.001
Windows Permissions
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1222.001
Windows Permissions
ToolDiskpart

Diskpart can be used to display, set, or clear attributes of a disk or volume.

T1222.002
Linux and Mac Permissions
CampaignKV Botnet Activity

KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines.

T1222.002
Linux and Mac Permissions
GroupAPT32

APT32's macOS backdoor changes the permission of the file it wants to execute to 755.

T1222.002
Linux and Mac Permissions
GroupTeamTNT

TeamTNT has modified the permissions on binaries with chattr.

T1222.002
Linux and Mac Permissions
GroupRocke

Rocke has changed file permissions of files so they could not be modified.

T1222.002
Linux and Mac Permissions
MalwareCOATHANGER

COATHANGER will set the GID of `httpsd` to 90 when infected.

T1222.002
Linux and Mac Permissions
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to modify file permissions.

T1222.002
Linux and Mac Permissions
MalwareBundlore

Bundlore changes the permissions of a payload using the command chmod -R 755.

T1222.002
Linux and Mac Permissions
MalwareBlack Basta

The Black Basta binary can use `chmod` to gain full permissions to targeted files.

T1222.002
Linux and Mac Permissions
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D has changed permissions of a second-stage payload to an executable via chmod.

T1222.002
Linux and Mac Permissions
MalwarePenquin

Penquin can add the executable flag to a downloaded file.

T1222.002
Linux and Mac Permissions
MalwareKinsing

Kinsing has used chmod to modify permissions on key files for use.

T1222.002
Linux and Mac Permissions
MalwareXCSSET

XCSSET uses the chmod +x command to grant executable permissions to the malicious file.

T1222.002
Linux and Mac Permissions
MalwareDRYHOOK

DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.

T1222.002
Linux and Mac Permissions
MalwareOSX/Shlayer

OSX/Shlayer can use the chmod utility to set a file as executable, such as chmod 777 or chmod +x.

T1222.002
Linux and Mac Permissions
MalwareDok

Dok gives all users execute permissions for the application using the command chmod +x /Users/Shared/AppStore.app.

T1480
Execution Guardrails
CampaignRedDelta Modified PlugX Infection Chain Operations

Mustang Panda included the use of Cloudflare geofencing mechanisms to limit payload download activity during RedDelta Modified PlugX Infection Chain Operations.

T1480
Execution Guardrails
GroupBlackByte

BlackByte stopped execution if identified language settings on victim machines was Russian or one of several language associated with former Soviet republics. BlackByte has used ransomware variants requiring a key passed on the command line for the malware to execute.

T1480
Execution Guardrails
GroupGamaredon Group

Gamaredon Group has used geoblocking to limit downloads of the malicious file to specific geographic locations.

T1480
Execution Guardrails
GroupContagious Interview

Contagious Interview has configured C2 endpoints to review IP geolocation, request headers, victim environment details and runtime conditions prior to delivering payloads.

T1480
Execution Guardrails
GroupAPT-C-36

APT-C-36 has used geolocation filtering in malware delivery to redirect traffic not coming from a targeted region or country, such as Ecuador or Colombia, to legitimate sites.

T1480
Execution Guardrails
MalwareTorisma

Torisma is only delivered to a compromised host if the victim's IP address is on an allow-list.

T1480
Execution Guardrails
MalwareStuxnet

Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met.

T1480
Execution Guardrails
MalwareRansomHub

RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration.

T1480
Execution Guardrails
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region.

T1480
Execution Guardrails
MalwareROAMINGHOUSE

ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected.

T1480
Execution Guardrails
MalwareTONESHELL

TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`.

T1480
Execution Guardrails
MalwareEnvyScout

EnvyScout can call window.location.pathname to ensure that embedded files are being executed from the C: drive, and will terminate if they are not.

T1480
Execution Guardrails
MalwareBOLDMOVE

BOLDMOVE verifies it is executing from a specific path during execution.

T1480
Execution Guardrails
MalwareSystemBC

SystemBC has checked if the last characters of DNS server names end in .bit before initializing C2 communication. SystemBC has identified running processes associated with anti-virus solutions to include `a2guard.exe` to determine whether it executes or not.

T1480
Execution Guardrails
MalwareShrinkLocker

ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria.

T1480
Execution Guardrails
MalwareApostle

Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function.

T1480
Execution Guardrails
MalwareRaspberry Robin

Raspberry Robin will check for the presence of several security products on victim machines and will avoid UAC bypass mechanisms if they are identified. Raspberry Robin can use specific cookie values in HTTP requests to command and control infrastructure to validate that requests for second stage payloads originate from the initial downloader script.

T1480
Execution Guardrails
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can execute a task which leads to execution if it finds a process name containing “creensaver.”

T1480
Execution Guardrails
MalwareLightSpy

On macOS, LightSpy checks the existence of a process identification number (PID) file, `/Users/Shared/irc.pid`, to verify if LightSpy is currently running.

T1480
Execution Guardrails
MalwareAnchor

Anchor can terminate itself if specific execution flags are not present.

T1480
Execution Guardrails
MalwareExbyte

Exbyte checks for the presence of a configuration file before completing execution.

T1480
Execution Guardrails
MalwareLunarLoader

LunarLoader can use the DNS domain name of a compromised host to create a decryption key to ensure a malicious payload can only execute against the intended targets.

T1480
Execution Guardrails
MalwarePureCrypter

PureCrypter code contains an ExclusionRegionNames option where it can compare the results of `kernel32!GetGeoInfo` with a list of regions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.