ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareMilan

Milan can identify users registered to a targeted machine.

T1033
System Owner/User Discovery
MalwareOilBooster

OilBooster can identify the compromised system's username which is then used as part of a unique identifier.

T1033
System Owner/User Discovery
MalwareRaccoon Stealer

Raccoon Stealer gathers information on the infected system owner and user.

T1033
System Owner/User Discovery
MalwareCardinal RAT

Cardinal RAT can collect the username from a victim machine.

T1033
System Owner/User Discovery
MalwareBISCUIT

BISCUIT has a command to gather the username from the system.

T1033
System Owner/User Discovery
MalwareGold Dragon

Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server.

T1033
System Owner/User Discovery
MalwareRGDoor

RGDoor executes the whoami on the victim’s machine.

T1033
System Owner/User Discovery
MalwareRevenge RAT

Revenge RAT gathers the username from the system.

T1033
System Owner/User Discovery
MalwareMacMa

MacMa can collect the username from the compromised machine.

T1033
System Owner/User Discovery
MalwareFunnyDream

FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`.

T1033
System Owner/User Discovery
MalwareMore_eggs

More_eggs has the capability to gather the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareSysUpdate

SysUpdate can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareKwampirs

Kwampirs collects registered owner details by using the commands systeminfo and net config workstation.

T1033
System Owner/User Discovery
MalwareBoomBox

BoomBox can enumerate the username on a compromised host.

T1033
System Owner/User Discovery
MalwareLAMEHUG

LAMEHUG can use `whoami` to enumerate the system user.

T1033
System Owner/User Discovery
MalwareMango

Mango can collect the user name from a compromised system which is used to create a unique victim identifier.

T1033
System Owner/User Discovery
MalwareGrimAgent

GrimAgent can identify the user id on a target machine.

T1033
System Owner/User Discovery
MalwareLokibot

Lokibot has the ability to discover the username on the infected host.

T1033
System Owner/User Discovery
MalwareEgregor

Egregor has used tools to gather information about users.

T1033
System Owner/User Discovery
MalwarePoetRAT

PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.

T1033
System Owner/User Discovery
MalwareFELIXROOT

FELIXROOT collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareZxShell

ZxShell can collect the owner and organization information from the target workstation.

T1033
System Owner/User Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.

T1033
System Owner/User Discovery
MalwareBabyShark

BabyShark has executed the whoami command.

T1033
System Owner/User Discovery
MalwareCannon

Cannon can gather the username from the system.

T1033
System Owner/User Discovery
MalwareCreepySnail

CreepySnail can execute `getUsername` on compromised systems.

T1033
System Owner/User Discovery
MalwarenjRAT

njRAT enumerates the current user during the initial infection.

T1033
System Owner/User Discovery
MalwareJPIN

JPIN can obtain the victim user name.

T1033
System Owner/User Discovery
MalwaremetaMain

metaMain can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareSideTwist

SideTwist can collect the username on a targeted system.

T1033
System Owner/User Discovery
MalwareMechaFlounder

MechaFlounder has the ability to identify the username and hostname on a compromised host.

T1033
System Owner/User Discovery
MalwareMis-Type

Mis-Type runs tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareLunarWeb

LunarWeb can collect user information from the targeted host.

T1033
System Owner/User Discovery
MalwareOctopus

Octopus can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareSTARWHALE

STARWHALE can gather the username from an infected host.

T1033
System Owner/User Discovery
MalwareMirageFox

MirageFox can gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareDownPaper

DownPaper collects the victim username and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwarePOWERSTATS

POWERSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name.

T1033
System Owner/User Discovery
MalwareShadowPad

ShadowPad has collected the username of the victim system.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1033
System Owner/User Discovery
MalwareGelsemium

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1033
System Owner/User Discovery
MalwareKomplex

The OsInfo function in Komplex collects the current running username.

T1033
System Owner/User Discovery
MalwareDenis

Denis enumerates and collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareLizar

Lizar can collect the username from the system.

T1033
System Owner/User Discovery
MalwareAzorult

Azorult can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareUPPERCUT

UPPERCUT has the capability to collect the current logged on user’s username from a machine.

T1033
System Owner/User Discovery
MalwareStrifeWater

StrifeWater can collect the user name from the victim's machine.

T1033
System Owner/User Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected the username from a victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.