Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupFIN8 | FIN8 has used WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareSardonic | Sardonic can use a WMI event filter to invoke a command-line event consumer to gain persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
Malwareadbupd | adbupd can use a WMI script to achieve persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareBADHATCH | BADHATCH can use WMI event subscriptions for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareHOPLIGHT | HOPLIGHT can use WMI event subscriptions to create persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareRegDuke | RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOSHSPY | POSHSPY uses a WMI event subscription to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareSeaDuke | SeaDuke uses an event filter in WMI code to execute a previously dropped executable shortly after system startup. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareTrailBlazer | TrailBlazer has the ability to use WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwaremetaMain | metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwareKevin | Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOWERTON | POWERTON can use WMI for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolSILENTTRINITY | SILENTTRINITY can create a WMI Event to execute a payload for persistence. |
| T1546.003 Windows Management Instrumentation Event Subscription |
ToolPoshC2 | PoshC2 has the ability to persist on a system using WMI events. |
| T1546.004 Unix Shell Configuration Modification |
CampaignShadowRay | During ShadowRay, threat actors executed commands on interactive and reverse shells. |
| T1546.004 Unix Shell Configuration Modification |
GroupContagious Interview | Contagious Interview has targeted macOS victim hosts using a bash downloader `coremedia.sh` and a bash script `cloud.sh`. |
| T1546.004 Unix Shell Configuration Modification |
MalwareRotaJakiro | When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder. |
| T1546.004 Unix Shell Configuration Modification |
MalwareLinux Rabbit | Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files. |
| T1546.004 Unix Shell Configuration Modification |
MalwareGreen Lambert | Green Lambert can establish persistence on a compromised host through modifying the `profile`, `login`, and run command (rc) files associated with the `bash`, `csh`, and `tcsh` shells. |
| T1546.004 Unix Shell Configuration Modification |
MalwarePHASEJAM | PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands. |
| T1546.004 Unix Shell Configuration Modification |
MalwareXCSSET | Using AppleScript, XCSSET adds it's executable to the user's `~/.zshrc_aliases` file (`"echo " & payload & " > ~/zshrc_aliases"`), it then adds a line to the .zshrc file to source the `.zshrc_aliases` file (`[ -f $HOME/.zshrc_aliases ] && . $HOME/.zshrc_aliases`). Each time the user starts a new `zsh` terminal session, the `.zshrc` file executes the `.zshrc_aliases` file. |
| T1546.007 Netsh Helper DLL |
Toolnetsh | netsh can be used as a persistence proxy technique to execute a helper DLL when netsh.exe is executed. |
| T1546.008 Accessibility Features |
GroupAPT3 | APT3 replaces the Sticky Keys binary |
| T1546.008 Accessibility Features |
GroupAPT41 | APT41 leveraged sticky keys to establish persistence. |
| T1546.008 Accessibility Features |
GroupAPT29 | APT29 used sticky-keys to obtain unauthenticated, privileged console access. |
| T1546.008 Accessibility Features |
GroupAxiom | Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence. |
| T1546.008 Accessibility Features |
GroupDeep Panda | Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions. |
| T1546.008 Accessibility Features |
GroupFox Kitten | Fox Kitten has used sticky keys to launch a command prompt. |
| T1546.008 Accessibility Features |
ToolEmpire | Empire can leverage WMI debugging to remotely replace binaries like sethc.exe, Utilman.exe, and Magnify.exe with cmd.exe. |
| T1546.009 AppCert DLLs |
MalwarePUNCHBUGGY | PUNCHBUGGY can establish using a AppCertDLLs Registry key. |
| T1546.010 AppInit DLLs |
GroupAPT39 | APT39 has used malware to set |
| T1546.010 AppInit DLLs |
MalwareT9000 | If a victim meets certain criteria, T9000 uses the AppInit_DLL functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious DLL, ResN32.dll. It does this by creating the following Registry keys: |
| T1546.010 AppInit DLLs |
MalwareCherry Picker | Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: |
| T1546.010 AppInit DLLs |
MalwareRamsay | Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key. |
| T1546.011 Application Shimming |
GroupFIN7 | FIN7 has used application shim databases for persistence. |
| T1546.011 Application Shimming |
MalwareShimRat | ShimRat has installed shim databases in the |
| T1546.011 Application Shimming |
MalwareSDBbot | SDBbot has the ability to use application shimming for persistence if it detects it is running as admin on Windows XP or 7, by creating a shim database to patch services.exe. |
| T1546.011 Application Shimming |
MalwarePillowmint | Pillowmint has used a malicious shim database to maintain persistence. |
| T1546.012 Image File Execution Options Injection |
CampaignC0032 | During the C0032 campaign, TEMP.Veles modified and added entries within |
| T1546.012 Image File Execution Options Injection |
MalwareSDBbot | SDBbot has the ability to use image file execution options for persistence if it detects it is running with admin privileges on a Windows version newer than Windows 7. |
| T1546.012 Image File Execution Options Injection |
MalwareSUNBURST | SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process |
| T1546.013 PowerShell Profile |
GroupTurla | Turla has used PowerShell profiles to maintain persistence on an infected machine. |
| T1546.015 Component Object Model Hijacking |
GroupAPT28 | APT28 has used COM hijacking for persistence by replacing the legitimate |
| T1546.015 Component Object Model Hijacking |
MalwareBBSRAT | BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList |
| T1546.015 Component Object Model Hijacking |
MalwareSVCReady | SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareFerocious | Ferocious can use COM hijacking to establish persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareKONNI | KONNI has modified ComSysApp service to load the malicious DLL payload. |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1546.015 Component Object Model Hijacking |
MalwareMosquito | Mosquito uses COM hijacking as a method of persistence. |
| T1546.015 Component Object Model Hijacking |
MalwareComRAT | ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.