Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSTARWHALE | STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDownPaper | DownPaper uses PowerShell to add a Registry Run key in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCozyCar | One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br> |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAgent Tesla | Agent Tesla can add itself to the Registry as a startup program to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePOWERTON | POWERTON can install a Registry Run key for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBADNEWS | BADNEWS installs a registry Run key to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRemexi | Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAstaroth | Astaroth creates a startup item for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHancitor | Hancitor has added Registry Run keys to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGelsemium | Gelsemium can set persistence with a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHelminth | Helminth establishes persistence by creating a shortcut in the Start Menu folder. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareComnie | Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareVasport | Vasport copies itself to disk and creates an associated run key Registry entry to establish. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBitPaymer | BitPaymer has set the run key |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBACKSPACE | BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareADVSTORESHELL | ADVSTORESHELL achieves persistence by adding itself to the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMivast | Mivast creates the following Registry entry: |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWarzoneRAT | WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmall Sieve | Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolSILENTTRINITY | SILENTTRINITY can establish a LNK file in the startup folder for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPowerSploit | PowerSploit's |
| T1547.001 Registry Run Keys / Startup Folder |
ToolEmpire | Empire can modify the registry run keys |
| T1547.001 Registry Run Keys / Startup Folder |
ToolRemcos | Remcos can add itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
ToolMCMD | MCMD can use Registry Run Keys for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolKoadic | Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPupy | Pupy adds itself to the startup folder or adds itself to the Registry key |
| T1547.001 Registry Run Keys / Startup Folder |
ToolQuasarRAT | If the QuasarRAT client process does not have administrator privileges it will add a registry key to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTeamPCP | TeamPCP has dropped malware into the Windows Startup folder to establish persistence. |
| T1547.002 Authentication Package |
MalwareFlame | Flame can use Windows Authentication Packages for persistence. |
| T1547.004 Winlogon Helper DLL |
GroupTropic Trooper | Tropic Trooper has created the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupTurla | Turla established persistence by adding a Shell value under the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupWizard Spider | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. |
| T1547.004 Winlogon Helper DLL |
MalwareKeyBoy | KeyBoy issues the command |
| T1547.004 Winlogon Helper DLL |
MalwareDarkTortilla | DarkTortilla has established persistence via the `Software\Microsoft\Windows NT\CurrentVersion\Winlogon` registry key. |
| T1547.004 Winlogon Helper DLL |
MalwareLockBit 3.0 | LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows |
| T1547.004 Winlogon Helper DLL |
MalwareGazer | Gazer can establish persistence by setting the value “Shell” with “explorer.exe, %malware_pathfile%” under the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareBazar | Bazar can use Winlogon Helper DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareRevenge RAT | Revenge RAT creates a Registry key at |
| T1547.004 Winlogon Helper DLL |
MalwareCannon | Cannon adds the Registry key |
| T1547.004 Winlogon Helper DLL |
MalwareDipsind | A Dipsind variant registers as a Winlogon Event Notify DLL to establish persistence. |
| T1547.004 Winlogon Helper DLL |
MalwareQilin | Qilin can configure a Winlogon registry entry. |
| T1547.004 Winlogon Helper DLL |
MalwareRemexi | Remexi achieves persistence using Userinit by adding the Registry key |
| T1547.005 Security Support Provider |
ToolPowerSploit | PowerSploit's |
| T1547.005 Security Support Provider |
ToolEmpire | Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's |
| T1547.005 Security Support Provider |
ToolMimikatz | The Mimikatz credential dumper contains an implementation of an SSP. |
| T1547.006 Kernel Modules and Extensions |
CampaignOperation CuckooBees | During Operation CuckooBees, attackers used a signed kernel rootkit to establish additional persistence. |
| T1547.006 Kernel Modules and Extensions |
MalwareSkidmap | Skidmap has the ability to install several loadable kernel modules (LKMs) on infected machines. |
| T1547.006 Kernel Modules and Extensions |
MalwareREPTILE | The REPTILE rootkit is implemented as a loadable kernel module (LKM). |
| T1547.006 Kernel Modules and Extensions |
MalwareDrovorub | Drovorub can use kernel modules to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.