Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1568.002 Domain Generation Algorithms |
MalwareMilan | Milan can use hardcoded domains as an input for domain generation algorithms. |
| T1568.002 Domain Generation Algorithms |
MalwareCCBkdr | CCBkdr can use a DGA for Fallback Channels if communications with the primary command and control server are lost. |
| T1568.002 Domain Generation Algorithms |
MalwareCHOPSTICK | CHOPSTICK can use a DGA for Fallback Channels, domains are generated by concatenating words from lists. |
| T1568.002 Domain Generation Algorithms |
MalwareBONDUPDATER | BONDUPDATER uses a DGA to communicate with command and control servers. |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
| T1568.002 Domain Generation Algorithms |
MalwareAstaroth | Astaroth has used a DGA in C2 communications. |
| T1568.002 Domain Generation Algorithms |
MalwareQakBot | QakBot can use domain generation algorithms in C2 communication. |
| T1568.002 Domain Generation Algorithms |
Toolngrok | ngrok can provide DGA for C2 servers through the use of random URL strings that change every 12 hours. |
| T1568.002 Domain Generation Algorithms |
ToolAsyncRAT | AsyncRAT use a DGA to generate a C2 domains. |
| T1568.003 DNS Calculation |
GroupAPT12 | APT12 has used multiple variants of DNS Calculation including multiplying the first two octets of an IP address and adding the third octet to that value in order to get a resulting command and control port. |
| T1569.001 Launchctl |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `launchctl` to restart the Launch Agent. |
| T1569.001 Launchctl |
MalwareCuckoo Stealer | Cuckoo Stealer can use `launchctl` to load a LaunchAgent for persistence. |
| T1569.001 Launchctl |
MalwareCalisto | Calisto uses launchctl to enable screen sharing on the victim’s machine. |
| T1569.001 Launchctl |
MalwareXCSSET | XCSSET loads a system level launchdaemon using the |
| T1569.001 Launchctl |
MalwareAppleJeus | AppleJeus has loaded a plist file using the |
| T1569.001 Launchctl |
MalwareLoudMiner | LoudMiner launched the QEMU services in the |
| T1569.002 Service Execution |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys. |
| T1569.002 Service Execution |
CampaignOperation Honeybee | During Operation Honeybee, threat actors ran |
| T1569.002 Service Execution |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service. |
| T1569.002 Service Execution |
CampaignAPT41 DUST | APT41 DUST used Windows services to execute DUSTPAN. |
| T1569.002 Service Execution |
CampaignOperation Wocao | During Operation Wocao, threat actors created services on remote systems for execution purposes. |
| T1569.002 Service Execution |
GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| T1569.002 Service Execution |
GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| T1569.002 Service Execution |
GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
| T1569.002 Service Execution |
GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| T1569.002 Service Execution |
GroupFIN7 | FIN7 has started the SSH service by executing `sc start sshd`. |
| T1569.002 Service Execution |
GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
| T1569.002 Service Execution |
GroupKe3chang | Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries. |
| T1569.002 Service Execution |
GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service. |
| T1569.002 Service Execution |
GroupChimera | Chimera has used PsExec to deploy beacons on compromised systems. |
| T1569.002 Service Execution |
GroupMedusa Group | Medusa Group has utilized PsExec to execute scripts and commands within victim environments. Medusa Group has also used the Windows service RoboCopy to search and copy data for exfiltration. |
| T1569.002 Service Execution |
GroupINC Ransom | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`. |
| T1569.002 Service Execution |
GroupSilence | Silence has used Winexe to install a service on the remote system. |
| T1569.002 Service Execution |
GroupWizard Spider | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network. |
| T1569.002 Service Execution |
GroupVelvet Ant | Velvet Ant executed and installed PlugX as a Windows service. |
| T1569.002 Service Execution |
GroupMoonstone Sleet | Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services. |
| T1569.002 Service Execution |
MalwareProxysvc | Proxysvc registers itself as a service on the victim’s machine to run as a standalone process. |
| T1569.002 Service Execution |
MalwareStrongPity | StrongPity can install a service to execute itself as a service. |
| T1569.002 Service Execution |
MalwareTinyTurla | TinyTurla can install itself as a service on compromised machines. |
| T1569.002 Service Execution |
MalwareBad Rabbit | Bad Rabbit drops a file named |
| T1569.002 Service Execution |
MalwareOlympic Destroyer | Olympic Destroyer utilizes PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareMafalda | Mafalda can create a remote service, let it run once, and then delete it. |
| T1569.002 Service Execution |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware executes as a service when deployed. |
| T1569.002 Service Execution |
MalwareHOPLIGHT | HOPLIGHT has used svchost.exe to execute a malicious DLL . |
| T1569.002 Service Execution |
MalwareWastedLocker | WastedLocker can execute itself as a service. |
| T1569.002 Service Execution |
MalwareInvisiMole | InvisiMole has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1569.002 Service Execution |
MalwareOkrum | Okrum's loader can create a new service named NtmsSvc to execute the payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.