ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
ToolImminent Monitor

Imminent Monitor has a feature to disable Windows Task Manager.

T1685
Disable or Modify Tools
ToolDonut

Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination.

T1685.001
Disable or Modify Windows Event Log
CampaignHomeLand Justice

During HomeLand Justice, threat actors deleted Windows events and application logs.

T1685.001
Disable or Modify Windows Event Log
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs.

T1685.001
Disable or Modify Windows Event Log
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems.

T1685.001
Disable or Modify Windows Event Log
GroupMagic Hound

Magic Hound has executed scripts to disable the event log service.

T1685.001
Disable or Modify Windows Event Log
GroupThreat Group-3390

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.

T1685.001
Disable or Modify Windows Event Log
ToolWevtutil

Wevtutil can be used to disable specific event logs on the system.

T1685.002
Disable or Modify Cloud Log
GroupAPT29

APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants.

T1685.002
Disable or Modify Cloud Log
ToolPacu

Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs.

T1685.003
Modify or Spoof Tool UI
MalwarePHASEJAM

PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary.

T1685.004
Disable or Modify Linux Audit System Log
MalwareEbury

Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active.

T1685.005
Clear Windows Event Logs
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise.

T1685.005
Clear Windows Event Logs
CampaignOperation Wocao

During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`.

T1685.005
Clear Windows Event Logs
GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

T1685.005
Clear Windows Event Logs
GroupIndrik Spider

Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`.

T1685.005
Clear Windows Event Logs
GroupVolt Typhoon

Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.

T1685.005
Clear Windows Event Logs
GroupAPT41

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.

T1685.005
Clear Windows Event Logs
GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

T1685.005
Clear Windows Event Logs
GroupAPT32

APT32 has cleared select event log entries.

T1685.005
Clear Windows Event Logs
GroupHAFNIUM

HAFNIUM has cleared actor-performed actions from logs.

T1685.005
Clear Windows Event Logs
GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

T1685.005
Clear Windows Event Logs
GroupFIN5

FIN5 has cleared event logs from victims.

T1685.005
Clear Windows Event Logs
GroupChimera

Chimera has cleared event logs on compromised hosts.

T1685.005
Clear Windows Event Logs
GroupMirrorFace

MirrorFace has deleted Windows event logs.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

T1685.005
Clear Windows Event Logs
GroupFIN8

FIN8 has cleared logs during post compromise cleanup activities.

T1685.005
Clear Windows Event Logs
MalwareSynAck

SynAck clears event logs.

T1685.005
Clear Windows Event Logs
MalwareRansomHub

RansomHub can delete events from the Security, System, and Application logs.

T1685.005
Clear Windows Event Logs
MalwareOlympic Destroyer

Olympic Destroyer will attempt to clear the System and Security event logs using wevtutil.

T1685.005
Clear Windows Event Logs
MalwareDUSTTRAP

DUSTTRAP can delete infected system log information.

T1685.005
Clear Windows Event Logs
MalwareMafalda

Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions.

T1685.005
Clear Windows Event Logs
MalwareShrinkLocker

ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs.

T1685.005
Clear Windows Event Logs
MalwareApostle

Apostle will attempt to delete all event logs on a victim machine following file wipe activity.

T1685.005
Clear Windows Event Logs
MalwareBlackCat

BlackCat can clear Windows event logs using `wevtutil.exe`.

T1685.005
Clear Windows Event Logs
MalwareLucifer

Lucifer can clear and remove event logs.

T1685.005
Clear Windows Event Logs
MalwareBlackEnergy

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.

T1685.005
Clear Windows Event Logs
MalwareNotPetya

NotPetya uses wevtutil to clear the Windows event logs.

T1685.005
Clear Windows Event Logs
MalwareRunningRAT

RunningRAT contains code to clear event logs.

T1685.005
Clear Windows Event Logs
MalwareMultiLayer Wiper

MultiLayer Wiper removes Windows event logs during execution.

T1685.005
Clear Windows Event Logs
MalwareLockBit 3.0

LockBit 3.0 can delete log files on targeted systems.

T1685.005
Clear Windows Event Logs
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can clear all system event logs.

T1685.005
Clear Windows Event Logs
Malwaregh0st RAT

gh0st RAT is able to wipe event logs.

T1685.005
Clear Windows Event Logs
MalwareHermeticWiper

HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

T1685.005
Clear Windows Event Logs
MalwareFinFisher

FinFisher clears the system event logs using OpenEventLog/ClearEventLog APIs .

T1685.005
Clear Windows Event Logs
MalwareZxShell

ZxShell has a command to clear system event logs.

T1685.005
Clear Windows Event Logs
MalwareMeteor

Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs.

T1685.005
Clear Windows Event Logs
MalwareKillDisk

KillDisk deletes Application, Security, Setup, and System Windows Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.