Real-world descriptions of how a group, tool or campaign used a technique.
109 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.003 Windows Service |
MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
| T1543.003 Windows Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence. |
| T1543.003 Windows Service |
MalwareFALLCHILL | FALLCHILL has been installed as a Windows service. |
| T1543.003 Windows Service |
ToolSILENTTRINITY | SILENTTRINITY can establish persistence by creating a new service. |
| T1543.003 Windows Service |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs. |
| T1543.003 Windows Service |
ToolEmpire | Empire can utilize built-in modules to modify service binaries and restore them to their original state. |
| T1543.003 Windows Service |
ToolRemcos | Remcos can terminate, suspend, and resume a process by PID. |
| T1543.003 Windows Service |
ToolPsExec | PsExec can leverage Windows services to escalate privileges from administrator to SYSTEM with the |
| T1543.003 Windows Service |
MalwareDuqu | Duqu creates a new service that loads a malicious driver when the system starts. When Duqu is active, the operating system believes that the driver is legitimate, as it has been signed with a valid private key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.