ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1671
Cloud Application Integration
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors deceived victims into authorizing malicious connected apps to their organization's Salesforce portal.

T1673
Virtual Machine Discovery
GroupUNC3886

UNC3886 has used scripts to enumerate ESXi hypervisors and their guest VMs.

T1673
Virtual Machine Discovery
MalwareCheerscrypt

Cheerscrypt has leveraged `esxcli vm process list` in order to gather a list of running virtual machines to terminate them.

T1673
Virtual Machine Discovery
MalwarePureCrypter

PureCrypter can identify virtual machines by querying the WMI object Win32_ComputerSystem for manufacturer and model and check it against the regular expression Microsoft|VMWare|Virtual.

T1673
Virtual Machine Discovery
MalwareVIRTUALPITA

VIRTUALPITA can target specific guest virtual machines for script execution.

T1673
Virtual Machine Discovery
MalwareQilin

Qilin can detect virtual machine environments including ESXi hosts, datacenters, and clusters within vCenter environments.

T1674
Input Injection
GroupFIN7

FIN7 has used malicious USBs to emulate keystrokes to launch PowerShell to download and execute malware from the adversary's server.

T1675
ESXi Administration Command
GroupUNC3886

UNC3886 used `vmtoolsd.exe` to run commands on guest virtual machines from a compromised ESXi host.

T1675
ESXi Administration Command
MalwareVIRTUALPITA

VIRTUALPITA can execute commands on guest virtual machines from compromised ESXi hypervisors.

T1677
Poisoned Pipeline Execution
MalwareShai-Hulud

Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`.

T1677
Poisoned Pipeline Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows.

T1677
Poisoned Pipeline Execution
MalwareCanisterWorm

CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

T1678
Delay Execution
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus's software generates a randomly selected date that is between 1-4 weeks in the future. This timestamp is then checked against the current time of the compromised machine, and the malware will sleep until that time is encountered.

T1678
Delay Execution
GroupKimsuky

Kimsuky has utilized the Sleep function to ensure execution of scripts.

T1678
Delay Execution
GroupMustang Panda

Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`.

T1678
Delay Execution
MalwareBRICKSTORM

BRICKSTORM has embedded delayed-start logic that attempts to circumvent detection for long-term persistence. BRICKSTORM has been observed configured with a “delay” timer built-in that waited for a hard-coded date months in the future before beginning to beacon to the configured C2 domain.

T1678
Delay Execution
MalwareTONESHELL

TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities.

T1678
Delay Execution
MalwareDynoWiper

DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot.

T1678
Delay Execution
MalwareSystemBC

SystemBC has leveraged the Sleep functions before and after commands to ensure execution using the hexadecimal values within commands to include `Sleep(0x2710u)` that waits 10 seconds, and `Sleep(0xEA60u)` for 60 seconds.

T1678
Delay Execution
MalwareRustyWater

RustyWater has generated random sleep intervals between C2 communication.

T1678
Delay Execution
MalwarePureCrypter

PureCrypter has the ability to delay for a specified number of seconds before execution.

T1678
Delay Execution
MalwareMuddyViper

MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute.

T1678
Delay Execution
MalwareFooder

Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution.

T1678
Delay Execution
MalwareGlassWorm

GlassWorm has used a timeout function set to `9e5` which delays execution 900,000 milliseconds or 15 minutes to avoid detection.

T1678
Delay Execution
MalwareAshTag

AshTag can use a set sleep time to delay C2 beaconing.

T1678
Delay Execution
MalwarePHASEJAM

PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process.

T1678
Delay Execution
MalwareSPAWNCHIMERA

SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution.

T1678
Delay Execution
MalwareHIUPAN

HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available.

T1678
Delay Execution
MalwareShai-Hulud

Shai-Hulud has delayed execution of its larger payloads by forking itself into background process.

T1678
Delay Execution
MalwareQilin

Qilin has the ability to delay execution.

T1678
Delay Execution
MalwareUPPERCUT

UPPERCUT can use a sleep function to delay execution.

T1678
Delay Execution
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has leveraged a persistence script that will sleep for five minutes before additional execution.

T1679
Selective Exclusion
GroupVOID MANTICORE

VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection.

T1679
Selective Exclusion
MalwareInvisibleFerret

InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types.

T1679
Selective Exclusion
MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

T1679
Selective Exclusion
MalwareDynoWiper

DynoWiper has recursively enumerated directories with the exception of the following: System32, Windows, Program Files, Program Files(x86), Temp, Recycle.Bin, $Recycle.Bin, Boot, PerfLogs, AppData, Documents and Settings.

T1679
Selective Exclusion
MalwareSameCoin

SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf."

T1679
Selective Exclusion
MalwareEmbargo

Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary.

T1679
Selective Exclusion
MalwareLazyWiper

LazyWiper can enumerate the hostname of the system to determine if it is a domain controller and exclude it from being wiped if so.

T1680
Local Storage Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk.

T1680
Local Storage Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model.

T1680
Local Storage Discovery
CampaignC0017

During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems.

T1680
Local Storage Discovery
GroupKimsuky

Kimsuky has enumerated drives.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

T1680
Local Storage Discovery
GroupPatchwork

Patchwork enumerated all available drives on the victim's machine.

T1680
Local Storage Discovery
GroupTeamTNT

TeamTNT has searched for disk partition and logical volume information.

T1680
Local Storage Discovery
GroupHigaisa

Higaisa collected the system volume serial number.

T1680
Local Storage Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s system volume information.

T1680
Local Storage Discovery
GroupConfucius

Confucius has used a file stealer that can examine system drives, including those other than the C drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.