ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1685.005
Clear Windows Event Logs
MalwareQilin

Qilin has the ability to clear Windows Event Logs.

T1685.005
Clear Windows Event Logs
MalwareHermeticWizard

HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.

T1685.005
Clear Windows Event Logs
ToolPupy

Pupy has a module to clear event logs with PowerShell.

T1685.005
Clear Windows Event Logs
ToolWevtutil

Wevtutil can be used to clear system and security event logs from the system.

T1685.006
Clear Linux or Mac System Logs
GroupSalt Typhoon

Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp.

T1685.006
Clear Linux or Mac System Logs
GroupTeamTNT

TeamTNT has removed system logs from /var/log/syslog.

T1685.006
Clear Linux or Mac System Logs
GroupRocke

Rocke has cleared log files within the /var/log/ folder.

T1685.006
Clear Linux or Mac System Logs
GroupSea Turtle

Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions.

T1685.006
Clear Linux or Mac System Logs
MalwareJumbledPath

JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure.

T1685.006
Clear Linux or Mac System Logs
MalwareUPSTYLE

UPSTYLE clears error logs after reading embedded commands for execution.

T1685.006
Clear Linux or Mac System Logs
MalwareMacMa

MacMa can clear possible malware traces such as application logs.

T1685.006
Clear Linux or Mac System Logs
MalwareProton

Proton removes logs from /var/logs and /Library/logs.

T1686
Disable or Modify System Firewall
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets.

T1686
Disable or Modify System Firewall
CampaignLeviathan Australian Intrusions

Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions.

T1686
Disable or Modify System Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

T1686
Disable or Modify System Firewall
GroupKimsuky

Kimsuky has been observed disabling the system firewall.

T1686
Disable or Modify System Firewall
GroupSalt Typhoon

Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices.

T1686
Disable or Modify System Firewall
GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

T1686
Disable or Modify System Firewall
GroupTeamTNT

TeamTNT has disabled iptables.

T1686
Disable or Modify System Firewall
GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

T1686
Disable or Modify System Firewall
GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1686
Disable or Modify System Firewall
GroupCarbanak

Carbanak may use netsh to add local firewall rule exceptions.

T1686
Disable or Modify System Firewall
GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

T1686
Disable or Modify System Firewall
GroupToddyCat

Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683.

T1686
Disable or Modify System Firewall
GroupVelvet Ant

Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices.

T1686
Disable or Modify System Firewall
MalwareKasidet

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

T1686
Disable or Modify System Firewall
MalwareHannotog

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

T1686
Disable or Modify System Firewall
MalwarePyDCrypt

PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines.

T1686
Disable or Modify System Firewall
MalwareTHINCRUST

THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

T1686
Disable or Modify System Firewall
MalwareHOPLIGHT

HOPLIGHT has modified the firewall using netsh.

T1686
Disable or Modify System Firewall
MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

T1686
Disable or Modify System Firewall
MalwarePlugX

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.

T1686
Disable or Modify System Firewall
MalwareBPFDoor

BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port.

T1686
Disable or Modify System Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686
Disable or Modify System Firewall
MalwareNanoCore

NanoCore can modify the victim's firewall.

T1686
Disable or Modify System Firewall
MalwareZxShell

ZxShell can disable the firewall by modifying the registry key HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile.

T1686
Disable or Modify System Firewall
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1686
Disable or Modify System Firewall
MalwareBACKSPACE

The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed.

T1686
Disable or Modify System Firewall
Toolnetsh

netsh can be used to disable local firewall settings.

T1686.001
Cloud Firewall
ToolPacu

Pacu can allowlist IP addresses in AWS GuardDuty.

T1686.002
Network Device Firewall
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging.

T1686.002
Network Device Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686.002
Network Device Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686.002
Network Device Firewall
MalwareCyclops Blink

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.

T1686.003
Windows Host Firewall
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 added rules to a victim's Windows firewall to set up a series of port-forwards allowing traffic to target systems.

T1686.003
Windows Host Firewall
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall.

T1686.003
Windows Host Firewall
GroupMoses Staff

Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.