ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwarePureCrypter

PureCrypter can retrieve the username from targeted machines.

T1033
System Owner/User Discovery
MalwareNanHaiShu

NanHaiShu collects the username from the victim.

T1033
System Owner/User Discovery
MalwareSVCReady

SVCReady can collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareNGLite

NGLite will run the whoami command to gather system information and return this to the command and control server.

T1033
System Owner/User Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of user accounts from a victim's machine.

T1033
System Owner/User Discovery
MalwareGazer

Gazer obtains the current user's security identifier.

T1033
System Owner/User Discovery
MalwareLatrodectus

Latrodectus can discover the username of an infected host.

T1033
System Owner/User Discovery
MalwareSaint Bot

Saint Bot can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareChaes

Chaes has collected the username and UID from the infected machine.

T1033
System Owner/User Discovery
MalwareLODEINFO

LODEINFO can identify the associated username on targeted machines.

T1033
System Owner/User Discovery
MalwareEVILNUM

EVILNUM can obtain the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used whoami commands to identify system owners.

T1033
System Owner/User Discovery
MalwareQUADAGENT

QUADAGENT gathers the victim username.

T1033
System Owner/User Discovery
MalwareSys10

Sys10 collects the account name of the logged-in user and sends it to the C2.

T1033
System Owner/User Discovery
MalwareMetamorfo

Metamorfo has collected the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information about the user on a compromised host.

T1033
System Owner/User Discovery
MalwareKONNI

KONNI can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareT9000

T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM.

T1033
System Owner/User Discovery
MalwareDnsSystem

DnsSystem can use the Windows user name to create a unique identification for infected users and systems.

T1033
System Owner/User Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the username on a compromised host.

T1033
System Owner/User Discovery
MalwareIxeshe

Ixeshe collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareMicropsia

Micropsia collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareRedLine Stealer

RedLine Stealer has obtained the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareRogueRobin

RogueRobin collects the victim’s username and whether that user is an admin.

T1033
System Owner/User Discovery
MalwareLitePower

LitePower can determine if the current user has admin privileges.

T1033
System Owner/User Discovery
MalwareSDBbot

SDBbot has the ability to identify the user on a compromised host.

T1033
System Owner/User Discovery
MalwareMosquito

Mosquito runs whoami on the victim’s machine.

T1033
System Owner/User Discovery
MalwareRTM

RTM can obtain the victim username and permissions.

T1033
System Owner/User Discovery
MalwareDerusbi

A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim.

T1033
System Owner/User Discovery
MalwareSodaMaster

SodaMaster can identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwareGrandoreiro

Grandoreiro can collect the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareWellMail

WellMail can identify the current username on the victim system.

T1033
System Owner/User Discovery
MalwareLiteDuke

LiteDuke can enumerate the account name on a targeted system.

T1033
System Owner/User Discovery
MalwareZxxZ

ZxxZ can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareWINDSHIELD

WINDSHIELD can gather the victim user name.

T1033
System Owner/User Discovery
MalwareBazar

Bazar can identify the username of the infected user.

T1033
System Owner/User Discovery
MalwareRATANKBA

RATANKBA runs the whoami and query user commands.

T1033
System Owner/User Discovery
MalwareXLoader

XLoader can identify the username from a victim machine.

T1033
System Owner/User Discovery
MalwareMoonWind

MoonWind obtains the victim username.

T1033
System Owner/User Discovery
MalwareHiddenFace

HiddenFace can collect the username associated with the compromised host.

T1033
System Owner/User Discovery
MalwareCryptoistic

Cryptoistic can gather data on the user of a compromised host.

T1033
System Owner/User Discovery
MalwareMgBot

MgBot includes modules for identifying local users and administrators on victim machines.

T1033
System Owner/User Discovery
MalwareZebrocy

Zebrocy gets the username from the system.

T1033
System Owner/User Discovery
MalwareSpeakUp

SpeakUp uses the whoami command.

T1033
System Owner/User Discovery
MalwareSUNBURST

SUNBURST collected the username from a compromised host.

T1033
System Owner/User Discovery
MalwareHotCroissant

HotCroissant has the ability to collect the username on the infected host.

T1033
System Owner/User Discovery
MalwareServHelper

ServHelper will attempt to enumerate the username of the victim.

T1033
System Owner/User Discovery
MalwareUnknown Logger

Unknown Logger can obtain information about the victim usernames.

T1033
System Owner/User Discovery
MalwareValak

Valak can gather information regarding the user.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.