ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1569.002
Service Execution
MalwareRemoteCMD

RemoteCMD can execute commands remotely by creating a new service on the remote system.

T1569.002
Service Execution
MalwareRagnar Locker

Ragnar Locker has used sc.exe to execute a service that it creates.

T1569.002
Service Execution
MalwareNotPetya

NotPetya can use PsExec to help propagate itself across a network.

T1569.002
Service Execution
MalwareHyperBro

HyperBro has the ability to start and stop a specified service.

T1569.002
Service Execution
MalwareAnchor

Anchor can create and execute services to load its payload.

T1569.002
Service Execution
MalwareBBSRAT

BBSRAT can start, stop, or delete services.

T1569.002
Service Execution
MalwareClambling

Clambling can create and start services on a compromised host.

T1569.002
Service Execution
MalwareDarkGate

DarkGate tries to elevate privileges to SYSTEM using PsExec to locally execute as a service, such as cmd /c c:\temp\PsExec.exe -accepteula -j -d -s [Target Binary].

T1569.002
Service Execution
MalwareLockBit 3.0

LockBit 3.0 can use PsExec to execute commands and payloads.

T1569.002
Service Execution
MalwareHydraq

Hydraq uses svchost.exe to execute a malicious DLL included in a new service group.

T1569.002
Service Execution
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1569.002
Service Execution
MalwareEmbargo

Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode.

T1569.002
Service Execution
Malwaregh0st RAT

gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service.

T1569.002
Service Execution
MalwareShamoon

Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec.

T1569.002
Service Execution
MalwareAttor

Attor's dispatcher can be executed as a service.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1569.002
Service Execution
MalwarePysa

Pysa has used PsExec to copy and execute the ransomware.

T1569.002
Service Execution
MalwarePandora

Pandora has the ability to install itself as a Windows service.

T1569.002
Service Execution
MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

T1569.002
Service Execution
MalwareWingbird

Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file.

T1569.002
Service Execution
MalwareIPsec Helper

IPsec Helper is run as a Windows service in victim environments.

T1569.002
Service Execution
MalwareSysUpdate

SysUpdate can manage services and processes.

T1569.002
Service Execution
MalwareZxShell

ZxShell can create a new service for execution.

T1569.002
Service Execution
MalwareWinnti for Windows

Winnti for Windows can run as a service using svchost.exe.

T1569.002
Service Execution
MalwareDEADWOOD

DEADWOOD can be executed as a service using various names, such as ScDeviceEnums.

T1569.002
Service Execution
MalwareLoudMiner

LoudMiner started the cryptomining virtual machine as a service on the infected machine.

T1569.002
Service Execution
MalwareNet Crawler

Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement.

T1569.002
Service Execution
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to start services.

T1569.002
Service Execution
MalwareHermeticWizard

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1569.002
Service Execution
ToolNet

The net start and net stop commands can be used in Net to execute or stop Windows services.

T1569.002
Service Execution
ToolImpacket

Impacket contains various modules emulating other service execution tools such as PsExec.

T1569.002
Service Execution
ToolEmpire

Empire can use PsExec to execute a payload on a remote host.

T1569.002
Service Execution
ToolPoshC2

PoshC2 contains an implementation of PsExec for remote execution.

T1569.002
Service Execution
ToolxCmd

xCmd can be used to execute binaries on remote systems by creating and starting a service.

T1569.002
Service Execution
ToolBrute Ratel C4

Brute Ratel C4 can create Windows system services for execution.

T1569.002
Service Execution
ToolWinexe

Winexe installs a service on the remote system, executes the command, then uninstalls the service.

T1569.002
Service Execution
ToolKoadic

Koadic can run a command on another machine using PsExec.

T1569.002
Service Execution
ToolPupy

Pupy uses PsExec to execute a payload or commands on a remote host.

T1569.002
Service Execution
ToolPsExec

Microsoft Sysinternals PsExec is a popular administration tool that can be used to execute binaries on remote systems using a temporary Windows service.

T1569.003
Systemctl
GroupTeamTNT

TeamTNT has created system services to execute cryptocurrency mining software.

T1569.003
Systemctl
MalwareCanisterWorm

CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service.

T1570
Lateral Tool Transfer
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI.

T1570
Lateral Tool Transfer
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network.

T1570
Lateral Tool Transfer
CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

T1570
Lateral Tool Transfer
CampaignC0015

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.

T1570
Lateral Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines.

T1570
Lateral Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation.

T1570
Lateral Tool Transfer
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share.

T1570
Lateral Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors used SMB to copy files to and from target systems.

T1570
Lateral Tool Transfer
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.