ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1686.003
Windows Host Firewall
GroupOilRig

OilRig has modified Windows firewall rules to enable remote access.

T1686.003
Windows Host Firewall
GroupMirrorFace

MirrorFace can modify the system firewall to allow communication to certain ports.

T1686.003
Windows Host Firewall
GroupLazarus Group

Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh.

T1686.003
Windows Host Firewall
GroupVOID MANTICORE

VOID MANTICORE has disabled Windows Defender protections to allow for follow-on activities within the compromised host.

T1686.003
Windows Host Firewall
GroupMagic Hound

Magic Hound has added the following rule to a victim's Windows firewall to allow RDP traffic - `"netsh" advfirewall firewall add rule name="Terminal Server" dir=in action=allow protocol=TCP localport=3389`.

T1686.003
Windows Host Firewall
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the Windows firewall during execution.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

T1686.003
Windows Host Firewall
MalwareRemsec

Remsec can add or remove applications or ports on the Windows firewall or disable it entirely.

T1686.003
Windows Host Firewall
MalwareTYPEFRAME

TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections.

T1686.003
Windows Host Firewall
MalwareBADCALL

BADCALL disables the Windows firewall before binding to a port.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

T1686.003
Windows Host Firewall
MalwareHARDRAIN

HARDRAIN opens the Windows Firewall to modify incoming connections.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

T1686.003
Windows Host Firewall
MalwareH1N1

H1N1 kills and disables services for Windows Firewall.

T1688
Safe Mode Boot
MalwareAvosLocker

AvosLocker can restart a compromised machine in safe mode.

T1688
Safe Mode Boot
MalwareRansomHub

RansomHub can reboot targeted systems into Safe Mode prior to encryption.

T1688
Safe Mode Boot
MalwareLockBit 3.0

LockBit 3.0 can reboot the infected host into Safe Mode.

T1688
Safe Mode Boot
MalwareEmbargo

Embargo has used a DLL variant of MDeployer to disable security solutions through Safe Mode.

T1688
Safe Mode Boot
MalwareBlack Basta

Black Basta can reboot victim machines in safe mode with networking via `bcdedit /set safeboot network`.

T1688
Safe Mode Boot
MalwareREvil

REvil can force a reboot in safe mode with networking.

T1688
Safe Mode Boot
MalwareQilin

Qilin can reboot targeted systems in safe mode to avoid detection.

T1689
Downgrade Attack
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment.

T1689
Downgrade Attack
MalwareBlackByte Ransomware

BlackByte Ransomware enables SMBv1 during execution.

T1689
Downgrade Attack
ToolSILENTTRINITY

SILENTTRINITY can downgrade NTLM to capture NTLM hashes.

T1690
Prevent Command History Logging
CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

T1690
Prevent Command History Logging
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

T1690
Prevent Command History Logging
GroupAPT38

APT38 has prepended a space to all of their terminal commands to operate without leaving traces in the HISTCONTROL environment.

T1690
Prevent Command History Logging
GroupUNC3886

UNC3886 has tampered with and disabled logging services on targeted systems.

T1690
Prevent Command History Logging
GroupSea Turtle

Sea Turtle unset the Bash and MySQL history files on victim systems.

T1690
Prevent Command History Logging
GroupMedusa Group

Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.

T1690
Prevent Command History Logging
MalwareBRICKSTORM

BRICKSTORM has impaired command logging through the use of `dev/null` which prevents generating output from the command and does not wait for input.

T1690
Prevent Command History Logging
MalwareLine Dancer

Line Dancer can disable syslog on compromised devices.

T1690
Prevent Command History Logging
MalwareBPFDoor

BPFDoor sets the `MYSQL_HISTFILE` and `HISTFILE` to `/dev/null` preventing the shell and MySQL from logging history in `/proc/<PID>/environ`.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

T1690
Prevent Command History Logging
MalwareVIRTUALPITA

VIRTUALPITA can impair logging by setting the `HISTFILE` environmental variable to `0` and stopping the `vmsyslogd` service.

T1690
Prevent Command History Logging
ToolSILENTTRINITY

SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.