ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareSakula

Most Sakula samples maintain persistence by setting the Registry Run key SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ in the HKLM or HKCU hive, with the Registry value and file name varying by sample.

T1547.001
Registry Run Keys / Startup Folder
MalwareBazar

Bazar can create or add files to Registry Run Keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBadPatch

BadPatch establishes a foothold by adding a link to the malware executable in the startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareXLoader

XLoader establishes persistence by copying its executable in a subdirectory of `%APPDATA%` or `%PROGRAMFILES%`, and then modifies Windows Registry Run keys or policies keys to execute the executable on system start.

T1547.001
Registry Run Keys / Startup Folder
MalwareRyuk

Ryuk has used the Windows command line to create a Registry entry under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinal1stspy

Final1stspy creates a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareLockBit 2.0

LockBit 2.0 can use a Registry Run key to establish persistence at startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinFisher

FinFisher establishes persistence by creating the Registry key HKCU\Software\Microsoft\Windows\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareCrossRAT

CrossRAT uses run keys for persistence on Windows.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilBunny

EvilBunny has created Registry keys for persistence in [HKLM|HKCU]\…\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareCobian RAT

Cobian RAT creates an autostart Registry key to ensure persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareServHelper

ServHelper may attempt to establish persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareJCry

JCry has created payloads in the Startup directory to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareUSBStealer

USBStealer registers itself under a Registry Run key with the name "USB Disk Security."

T1547.001
Registry Run Keys / Startup Folder
MalwareTaidoor

Taidoor has modified the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareSHIPSHAPE

SHIPSHAPE achieves persistence by creating a shortcut in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoisonIvy

PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwareSeasalt

Seasalt creates a Registry entry to ensure infection after reboot under HKLM\Software\Microsoft\Windows\currentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanoCore

NanoCore creates a RunOnce key in the Registry to execute its VBS scripts each time the user logs on to the machine.

T1547.001
Registry Run Keys / Startup Folder
MalwareLoJax

LoJax has modified the Registry key ‘HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute’ from ‘autocheck autochk *’ to ‘autocheck autoche *’ in order to execute its payload during Windows startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareCardinal RAT

Cardinal RAT establishes Persistence by setting the HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load Registry key to point to its executable.

T1547.001
Registry Run Keys / Startup Folder
MalwarePisloader

Pisloader establishes persistence via a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareGold Dragon

Gold Dragon establishes persistence in the Startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareRamsay

Ramsay has created Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCarberp

Carberp has maintained persistence by placing itself inside the current user's startup folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareFunnyDream

FunnyDream can use a Registry Run Key and the Startup folder to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareROADSWEEP

ROADSWEEP has been placed in the start up folder to trigger execution upon user login.

T1547.001
Registry Run Keys / Startup Folder
MalwareSysUpdate

SysUpdate can use a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTinyZBot

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBoomBox

BoomBox can establish persistence by writing the Registry value MicroNativeCacheSvc to HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareInnaputRAT

Some InnaputRAT variants establish persistence by modifying the Registry key HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run:%appdata%\NeutralApp\NeutralApp.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrimAgent

GrimAgent can set persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareLookBack

LookBack sets up a Registry Run key to establish a persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoetRAT

PoetRAT has added a registry key in the <RUN> hive for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFELIXROOT

FELIXROOT adds a shortcut file to the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBabyShark

BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwarebuild_downer

build_downer has the ability to add itself to the Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareWinnti for Windows

Winnti for Windows can add a service named wind0ws to the Registry to achieve persistence after reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1547.001
Registry Run Keys / Startup Folder
MalwareMaze

Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHIUPAN

HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareTURNEDUP

TURNEDUP is capable of writing to a Registry Run key to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareChChes

ChChes establishes persistence by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareANDROMEDA

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

T1547.001
Registry Run Keys / Startup Folder
MalwareKOCTOPUS

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeyoka Backdoor

Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareHTTPBrowser

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareOctopus

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.