ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareBADHATCH

BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`.

T1033
System Owner/User Discovery
MalwareAction RAT

Action RAT has the ability to collect the username from an infected host.

T1033
System Owner/User Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about the current user name.

T1033
System Owner/User Discovery
MalwarePUBLOAD

PUBLOAD has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwareWellMess

WellMess can collect the username on the victim machine to send to C2.

T1033
System Owner/User Discovery
MalwareWoody RAT

Woody RAT can retrieve a list of user accounts and usernames from an infected machine.

T1033
System Owner/User Discovery
MalwareMafalda

Mafalda can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareSquirrelwaffle

Squirrelwaffle can collect the user name from a compromised host.

T1033
System Owner/User Discovery
MalwareHexEval Loader

HexEval Loader has collected the username from the victim host.

T1033
System Owner/User Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareAgent.btz

Agent.btz obtains the victim username and saves it to a file.

T1033
System Owner/User Discovery
MalwareSombRAT

SombRAT can execute getinfo to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareFlawedAmmyy

FlawedAmmyy enumerates the current user during the initial infection.

T1033
System Owner/User Discovery
MalwareRifdoor

Rifdoor has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can discover and send the username from a compromised host to C2.

T1033
System Owner/User Discovery
MalwareInvisiMole

InvisiMole lists local users and session information.

T1033
System Owner/User Discovery
MalwareWINERACK

WINERACK can gather information on the victim username.

T1033
System Owner/User Discovery
MalwareOkrum

Okrum can collect the victim username.

T1033
System Owner/User Discovery
MalwareBonadan

Bonadan has discovered the username of the user running the backdoor.

T1033
System Owner/User Discovery
MalwareNeoichor

Neoichor can collect the user name from a victim's machine.

T1033
System Owner/User Discovery
MalwareRaspberry Robin

Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges.

T1033
System Owner/User Discovery
MalwareDiavol

Diavol can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s username.

T1033
System Owner/User Discovery
MalwareBlackCat

BlackCat can utilize `net use` commands to discover the user name on a compromised host.

T1033
System Owner/User Discovery
MalwareVERMIN

VERMIN gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareNightdoor

Nightdoor gathers information on victim system users and usernames.

T1033
System Owner/User Discovery
MalwareMarkiRAT

MarkiRAT can retrieve the victim’s username.

T1033
System Owner/User Discovery
MalwarePowerShower

PowerShower has the ability to identify the current user on the infected host.

T1033
System Owner/User Discovery
MalwareKazuar

Kazuar gathers information on users.

T1033
System Owner/User Discovery
MalwareDarkComet

DarkComet gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1033
System Owner/User Discovery
MalwareLucifer

Lucifer has the ability to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwarezwShell

zwShell can obtain the name of the logged-in user on the victim.

T1033
System Owner/User Discovery
MalwareDRATzarus

DRATzarus can obtain a list of users from an infected machine.

T1033
System Owner/User Discovery
MalwareRising Sun

Rising Sun can detect the username of the infected host.

T1033
System Owner/User Discovery
MalwareChrommme

Chrommme can retrieve the username from a targeted system.

T1033
System Owner/User Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted usernames on infected endpoints.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1033
System Owner/User Discovery
MalwareFlagpro

Flagpro has been used to run the whoami command on the system.

T1033
System Owner/User Discovery
MalwareXAgentOSX

XAgentOSX contains the getInfoOSX function to return the OS X version as well as the current user.

T1033
System Owner/User Discovery
MalwareROKRAT

ROKRAT can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareDarkWatchman

DarkWatchman has collected the username from a victim machine.

T1033
System Owner/User Discovery
MalwareDyre

Dyre has the ability to identify the users on a compromised host.

T1033
System Owner/User Discovery
MalwarePlugX

PlugX has the ability to gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareReaver

Reaver collects the victim's username.

T1033
System Owner/User Discovery
MalwareS-Type

S-Type has run tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareRemsec

Remsec can obtain information about the current user.

T1033
System Owner/User Discovery
MalwareExplosive

Explosive has collected the username from the infected host.

T1033
System Owner/User Discovery
MalwareEpic

Epic collects the user name from the victim’s machine.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.