Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareStrongPity | StrongPity can use the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePLAINTEE | PLAINTEE gains persistence by adding the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNebulae | Nebulae can achieve persistence through a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTONESHELL | TONESHELL has added Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKasidet | Kasidet creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAppleSeed | AppleSeed has the ability to create the Registry key name |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETWIRE | NETWIRE creates a Registry start-up entry to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilGrab | EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSslMM | To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAria-body | Aria-body has established persistence via the Startup folder or Run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmotet | Emotet has been observed adding the downloaded payload to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSNUGRIDE | SNUGRIDE establishes persistence through a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrimson | Crimson can add Registry run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTurian | Turian can establish persistence by adding Registry Run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMachete | Machete used the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePrikormka | Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD | PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGootloader | Gootloader can create an autorun entry for a PowerShell script to run at reboot. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAuTo Stealer | AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFLASHFLOOD | FLASHFLOOD achieves persistence by making an entry in the Registry's Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlawedAmmyy | FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSnip3 | Snip3 can create a VBS file in startup to persist after system restarts. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRifdoor | Rifdoor has created a new registry entry at |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGuLoader | GuLoader can establish persistence via the Registry under |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisiMole | InvisiMole can place a lnk file in the Startup Folder to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCLAIMLOADER | CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareOkrum | Okrum establishes persistence by creating a .lnk shortcut to itself in the Startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRaspberry Robin | Raspberry Robin will use a Registry key to achieve persistence through reboot, setting a RunOnce key such as: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMispadu | Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRustyWater | RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareIcedID | IcedID has established persistence by creating a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMarkiRAT | MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerShower | PowerShower sets up persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKazuar | Kazuar adds a sub-key under several Registry run keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNavRAT | NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkComet | DarkComet adds several Registry entries to enable automatic execution at every system startup. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETEAGLE | The "SCOUT" variant of NETEAGLE achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFatDuke | FatDuke has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLucifer | Lucifer can persist by setting Registry key values |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBlackEnergy | The BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareShimRat | ShimRat has installed a registry based start-up key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareObliqueRAT | ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvaddon | Avaddon uses registry run keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareConficker | Conficker adds Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlagpro | Flagpro has dropped an executable file to the startup directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHi-Zor | Hi-Zor creates a Registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUNCHBUGGY | PUNCHBUGGY has been observed using a Registry Run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePteranodon | Pteranodon copies itself to the Startup folder to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Run` registry key and by creating a .lnk shortcut file in the Windows startup folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCORESHELL | CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.