ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1546.003
Windows Management Instrumentation Event Subscription
GroupFIN8

FIN8 has used WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSardonic

Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence.

T1546.003
Windows Management Instrumentation Event Subscription
Malwareadbupd

adbupd can use a WMI script to achieve persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareBADHATCH

BADHATCH can use WMI event subscriptions for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareHOPLIGHT

HOPLIGHT can use WMI event subscriptions to create persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareRegDuke

RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOSHSPY

POSHSPY uses a WMI event subscription to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareSeaDuke

SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareTrailBlazer

TrailBlazer has the ability to use WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwaremetaMain

metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence.

T1546.003
Windows Management Instrumentation Event Subscription
MalwareKevin

Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOWERTON

POWERTON can use WMI for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
ToolSILENTTRINITY

SILENTTRINITY can create a WMI Event to execute a payload for persistence.

T1546.003
Windows Management Instrumentation Event Subscription
ToolPoshC2

PoshC2 has the ability to persist on a system using WMI events.

T1546.004
Unix Shell Configuration Modification
CampaignShadowRay

During ShadowRay, threat actors executed commands on interactive and reverse shells.

T1546.004
Unix Shell Configuration Modification
GroupContagious Interview

Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`.

T1546.004
Unix Shell Configuration Modification
MalwareRotaJakiro

When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder.

T1546.004
Unix Shell Configuration Modification
MalwareLinux Rabbit

Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files.

T1546.004
Unix Shell Configuration Modification
MalwareGreen Lambert

Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells.

T1546.004
Unix Shell Configuration Modification
MalwarePHASEJAM

PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands.

T1546.004
Unix Shell Configuration Modification
MalwareXCSSET

Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file.

T1546.007
Netsh Helper DLL
Toolnetsh

netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed.

T1546.008
Accessibility Features
GroupAPT3

APT3 replaces the Sticky Keys binary C:\Windows\System32\sethc.exe for persistence.

T1546.008
Accessibility Features
GroupAPT41

APT41 leveraged sticky keys to establish persistence.

T1546.008
Accessibility Features
GroupAPT29

APT29 used sticky-keys to obtain unauthenticated, privileged console access.

T1546.008
Accessibility Features
GroupAxiom

Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence.

T1546.008
Accessibility Features
GroupDeep Panda

Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions.

T1546.008
Accessibility Features
GroupFox Kitten

Fox Kitten has used sticky keys to launch a command prompt.

T1546.008
Accessibility Features
ToolEmpire

Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe.

T1546.009
AppCert DLLs
MalwarePUNCHBUGGY

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

T1546.010
AppInit DLLs
GroupAPT39

APT39 has used malware to set LoadAppInit_DLLs in the Registry key SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows in order to establish persistence.

T1546.010
AppInit DLLs
MalwareT9000

If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs – %APPDATA%\Intel\ResN32.dll and HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs – 0x1.

T1546.010
AppInit DLLs
MalwareCherry Picker

Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"

T1546.010
AppInit DLLs
MalwareRamsay

Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key.

T1546.011
Application Shimming
GroupFIN7

FIN7 has used application shim databases for persistence.

T1546.011
Application Shimming
MalwareShimRat

ShimRat has installed shim databases in the AppPatch folder.

T1546.011
Application Shimming
MalwareSDBbot

SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe.

T1546.011
Application Shimming
MalwarePillowmint

Pillowmint has used a malicious shim database to maintain persistence.

T1546.012
Image File Execution Options Injection
CampaignC0032

During the C0032 campaign, TEMP.Veles modified and added entries within HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options to maintain persistence.

T1546.012
Image File Execution Options Injection
MalwareSDBbot

SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7.

T1546.012
Image File Execution Options Injection
MalwareSUNBURST

SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process dllhost.exe to trigger the installation of Cobalt Strike.

T1546.013
PowerShell Profile
GroupTurla

Turla has used PowerShell profiles to maintain persistence on an infected machine.

T1546.015
Component Object Model Hijacking
GroupAPT28

APT28 has used COM hijacking for persistence by replacing the legitimate MMDeviceEnumerator object with a payload.

T1546.015
Component Object Model Hijacking
MalwareBBSRAT

BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList {42aedc87-2188-41fd-b9a3-0c966feabec1} or Microsoft WBEM New Event Subsystem {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} depending on the system's CPU architecture.

T1546.015
Component Object Model Hijacking
MalwareSVCReady

SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence.

T1546.015
Component Object Model Hijacking
MalwareFerocious

Ferocious can use COM hijacking to establish persistence.

T1546.015
Component Object Model Hijacking
MalwareKONNI

KONNI has modified ComSysApp service to load the malicious DLL payload.

T1546.015
Component Object Model Hijacking
MalwareJHUHUGIT

JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}).

T1546.015
Component Object Model Hijacking
MalwareMosquito

Mosquito uses COM hijacking as a method of persistence.

T1546.015
Component Object Model Hijacking
MalwareComRAT

ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.