ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareSTARWHALE

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareDownPaper

DownPaper uses PowerShell to add a Registry Run key in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCozyCar

One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERTON

POWERTON can install a Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBADNEWS

BADNEWS installs a registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRemexi

Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareAstaroth

Astaroth creates a startup item for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHancitor

Hancitor has added Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGelsemium

Gelsemium can set persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHelminth

Helminth establishes persistence by creating a shortcut in the Start Menu folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareComnie

Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareVasport

Vasport copies itself to disk and creates an associated run key Registry entry to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareBitPaymer

BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMivast

Mivast creates the following Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Micromedia.

T1547.001
Registry Run Keys / Startup Folder
MalwareWarzoneRAT

WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmall Sieve

Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolSILENTTRINITY

SILENTTRINITY can establish a LNK file in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolEmpire

Empire can modify the registry run keys HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolRemcos

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolMCMD

MCMD can use Registry Run Keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolKoadic

Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolPupy

Pupy adds itself to the startup folder or adds itself to the Registry key SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolQuasarRAT

If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamPCP

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.

T1547.002
Authentication Package
MalwareFlame

Flame can use Windows Authentication Packages for persistence.

T1547.004
Winlogon Helper DLL
GroupTropic Trooper

Tropic Trooper has created the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell and sets the value to establish persistence.

T1547.004
Winlogon Helper DLL
GroupTurla

Turla established persistence by adding a Shell value under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
GroupWizard Spider

Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1547.004
Winlogon Helper DLL
MalwareDarkTortilla

DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key.

T1547.004
Winlogon Helper DLL
MalwareLockBit 3.0

LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon` Registry key.

T1547.004
Winlogon Helper DLL
MalwareGazer

Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1547.004
Winlogon Helper DLL
MalwareBazar

Bazar can use Winlogon Helper DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareRevenge RAT

Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.

T1547.004
Winlogon Helper DLL
MalwareCannon

Cannon adds the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareDipsind

A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence.

T1547.004
Winlogon Helper DLL
MalwareQilin

Qilin can configure a Winlogon registry entry.

T1547.004
Winlogon Helper DLL
MalwareRemexi

Remexi achieves persistence using Userinit by adding the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit.

T1547.005
Security Support Provider
ToolPowerSploit

PowerSploit's Install-SSP Persistence module can be used to establish by installing a SSP DLL.

T1547.005
Security Support Provider
ToolEmpire

Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's Install-SSP and Invoke-Mimikatz to install malicious SSPs and log authentication events.

T1547.005
Security Support Provider
ToolMimikatz

The Mimikatz credential dumper contains an implementation of an SSP.

T1547.006
Kernel Modules and Extensions
CampaignOperation CuckooBees

During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence.

T1547.006
Kernel Modules and Extensions
MalwareSkidmap

Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines.

T1547.006
Kernel Modules and Extensions
MalwareREPTILE

The REPTILE rootkit is implemented as a loadable kernel module (LKM).

T1547.006
Kernel Modules and Extensions
MalwareDrovorub

Drovorub can use kernel modules to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.