ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwareComnie

Comnie attempts to detect several anti-virus products.

T1518.001
Security Software Discovery
MalwareLizar

Lizar can search for processes associated with an anti-virus product from list.

T1518.001
Security Software Discovery
ToolSILENTTRINITY

SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID.

T1518.001
Security Software Discovery
ToolPacu

Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors.

T1518.001
Security Software Discovery
ToolTasklist

Tasklist can be used to enumerate security software currently running on a system by process name of known products.

T1518.001
Security Software Discovery
ToolEmpire

Empire can enumerate antivirus software on the target.

T1518.001
Security Software Discovery
Toolnetsh

netsh can be used to discover system firewall settings.

T1518.001
Security Software Discovery
ToolBrute Ratel C4

Brute Ratel C4 can detect EDR userland hooks.

T1518.001
Security Software Discovery
MalwareFlame

Flame identifies security software such as antivirus through the Security module.

T1518.002
Backup Software Discovery
GroupWizard Spider

Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine.

T1526
Cloud Service Discovery
GroupStorm-0501

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.

T1526
Cloud Service Discovery
ToolPacu

Pacu can enumerate AWS services, such as CloudTrail and CloudWatch.

T1526
Cloud Service Discovery
ToolAADInternals

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

T1526
Cloud Service Discovery
ToolROADTools

ROADTools can enumerate Azure AD applications and service principals.

T1526
Cloud Service Discovery
ToolTruffleHog

TruffleHog has the ability to scan code repositories and CI/CD platforms.

T1526
Cloud Service Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search GitHub for Actions runner processes.

T1528
Steal Application Access Token
CampaignLeviathan Australian Intrusions

Leviathan abused access to compromised appliances to collect JSON Web Tokens (JWTs), used for creating virtual desktop sessions, during Leviathan Australian Intrusions.

T1528
Steal Application Access Token
GroupAPT29

APT29 uses stolen tokens to access victim accounts, without needing a password.

T1528
Steal Application Access Token
GroupAPT28

APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection".

T1528
Steal Application Access Token
MalwareShai-Hulud

Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories.

T1528
Steal Application Access Token
ToolAADInternals

AADInternals can steal users’ access tokens via phishing emails containing malicious links.

T1528
Steal Application Access Token
ToolTruffleHog

TruffleHog has gathered access tokens and API tokens from CI/CD pipeline solutions and repositories.

T1528
Steal Application Access Token
ToolPeirates

Peirates gathers Kubernetes service account tokens using a variety of techniques.

T1528
Steal Application Access Token
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens.

T1528
Steal Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD.

T1528
Steal Application Access Token
MalwareCanisterWorm

CanisterWorm has gathered cloud access tokens.

T1528
Steal Application Access Token
GroupTeamPCP

TeamPCP has used malware to steal access tokens from targeted cloud and developer environments.

T1528
Steal Application Access Token
GroupShinyHunters

ShinyHunters has stolen valid OAuth credentials from DevOps personnel or a company GitHub repository. Additionally, ShinyHunters has stolen application access tokens to access cloud services and to bypass authentication mechanisms.

T1528
Steal Application Access Token
MalwareKali365

Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure.

T1529
System Shutdown/Reboot
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems.

T1529
System Shutdown/Reboot
GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK, which will initiate a system reboot after wiping the victim's MBR.

T1529
System Shutdown/Reboot
GroupAPT37

APT37 has used malware that will issue the command shutdown /r /t 1 to reboot a system after wiping its MBR.

T1529
System Shutdown/Reboot
GroupMedusa Group

Medusa Group has manually turned off and encrypted virtual machines.

T1529
System Shutdown/Reboot
GroupLazarus Group

Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems.

T1529
System Shutdown/Reboot
MalwareAcidRain

AcidRain reboots the target system once the various wiping processes are complete.

T1529
System Shutdown/Reboot
MalwareAvosLocker

AvosLocker’s Linux variant has terminated ESXi virtual machines.

T1529
System Shutdown/Reboot
MalwareOlympic Destroyer

Olympic Destroyer will shut down the compromised system after it is done modifying system configuration settings.

T1529
System Shutdown/Reboot
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system.

T1529
System Shutdown/Reboot
MalwareShrinkLocker

ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users.

T1529
System Shutdown/Reboot
MalwareApostle

Apostle reboots the victim machine following wiping and related activity.

T1529
System Shutdown/Reboot
MalwareWhisperGate

WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag.

T1529
System Shutdown/Reboot
MalwareAcidPour

AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain.

T1529
System Shutdown/Reboot
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can reboot or shutdown the targeted system or logoff the current user.

T1529
System Shutdown/Reboot
MalwareDCSrv

DCSrv has a function to sleep for two hours before rebooting the system.

T1529
System Shutdown/Reboot
MalwareNotPetya

NotPetya will reboot the system one hour after infection.

T1529
System Shutdown/Reboot
MalwareLockerGoga

LockerGoga has been observed shutting down infected systems.

T1529
System Shutdown/Reboot
MalwareMultiLayer Wiper

MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery.

T1529
System Shutdown/Reboot
MalwareDarkGate

DarkGate has used the `shutdown`command to shut down and/or restart the victim system.

T1529
System Shutdown/Reboot
MalwareLatrodectus

Latrodectus has the ability to restart compromised hosts.

T1529
System Shutdown/Reboot
MalwareShamoon

Shamoon will reboot the infected system once the wiping functionality has been completed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.