ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareStrongPity

StrongPity can use the HKCU\Software\Microsoft\Windows\CurrentVersion\Run Registry key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePLAINTEE

PLAINTEE gains persistence by adding the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareNebulae

Nebulae can achieve persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareTONESHELL

TONESHELL has added Registry Run keys to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareKasidet

Kasidet creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareAppleSeed

AppleSeed has the ability to create the Registry key name EstsoftAutoUpdate at HKCU\Software\Microsoft/Windows\CurrentVersion\RunOnce to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilGrab

EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSslMM

To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut.

T1547.001
Registry Run Keys / Startup Folder
MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmotet

Emotet has been observed adding the downloaded payload to the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSNUGRIDE

SNUGRIDE establishes persistence through a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrimson

Crimson can add Registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTurian

Turian can establish persistence by adding Registry Run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareMachete

Machete used the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePrikormka

Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUBLOAD

PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareGootloader

Gootloader can create an autorun entry for a PowerShell script to run at reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwareAuTo Stealer

AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFLASHFLOOD

FLASHFLOOD achieves persistence by making an entry in the Registry's Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlawedAmmyy

FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareSnip3

Snip3 can create a VBS file in startup to persist after system restarts.

T1547.001
Registry Run Keys / Startup Folder
MalwareRifdoor

Rifdoor has created a new registry entry at HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Graphics with a value of C:\ProgramData\Initech\Initech.exe /run.

T1547.001
Registry Run Keys / Startup Folder
MalwareGuLoader

GuLoader can establish persistence via the Registry under HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1547.001
Registry Run Keys / Startup Folder
MalwareInvisiMole

InvisiMole can place a lnk file in the Startup Folder to achieve persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCLAIMLOADER

CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareOkrum

Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRaspberry Robin

Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce
{random value name} = “rundll32 shell32 ShellExec_RunDLLA REGSVR /u /s “{dropped copy path and file name}””
.

T1547.001
Registry Run Keys / Startup Folder
MalwareMispadu

Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareRustyWater

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareIcedID

IcedID has established persistence by creating a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMarkiRAT

MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started.

T1547.001
Registry Run Keys / Startup Folder
MalwarePowerShower

PowerShower sets up persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareKazuar

Kazuar adds a sub-key under several Registry run keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareNavRAT

NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkComet

DarkComet adds several Registry entries to enable automatic execution at every system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETEAGLE

The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFatDuke

FatDuke has used HKLM\SOFTWARE\Microsoft\CurrentVersion\Run to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLucifer

Lucifer can persist by setting Registry key values HKLM\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\QQMusic.

T1547.001
Registry Run Keys / Startup Folder
MalwareBlackEnergy

The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareShimRat

ShimRat has installed a registry based start-up key HKCU\Software\microsoft\windows\CurrentVersion\Run to maintain persistence should other methods fail.

T1547.001
Registry Run Keys / Startup Folder
MalwareObliqueRAT

ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvaddon

Avaddon uses registry run keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareConficker

Conficker adds Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFlagpro

Flagpro has dropped an executable file to the startup directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareHi-Zor

Hi-Zor creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUNCHBUGGY

PUNCHBUGGY has been observed using a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePteranodon

Pteranodon copies itself to the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareCORESHELL

CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.