ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1005
Data from Local System
GroupLAPSUS$

LAPSUS$ uploaded sensitive files, information, and credentials from a targeted organization for extortion or public release.

T1005
Data from Local System
GroupWizard Spider

Wizard Spider has collected data from a compromised host prior to exfiltration.

T1005
Data from Local System
GroupInception

Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host.

T1005
Data from Local System
GroupVOID MANTICORE

VOID MANTICORE has collected cached data and files from within the victim environment.

T1005
Data from Local System
GroupMagic Hound

Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine.

T1005
Data from Local System
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1005
Data from Local System
GroupTeamPCP

TeamPCP has stolen source code from victim environments including Mistral AI.

T1006
Direct Volume Access
GroupVolt Typhoon

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

T1006
Direct Volume Access
GroupScattered Spider

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

T1007
System Service Discovery
GroupIndrik Spider

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

T1007
System Service Discovery
GroupKimsuky

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.

T1007
System Service Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: net start >> %temp%\download

T1007
System Service Discovery
GroupVolt Typhoon

Volt Typhoon has used `net start` to list running services.

T1007
System Service Discovery
GroupTeamTNT

TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them.

T1007
System Service Discovery
GroupOilRig

OilRig has used sc query on a victim to gather information about services.

T1007
System Service Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

T1007
System Service Discovery
GroupKe3chang

Ke3chang performs service discovery using net start commands.

T1007
System Service Discovery
GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1007
System Service Discovery
GroupTurla

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1007
System Service Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group discovers all running services.

T1007
System Service Discovery
GroupChimera

Chimera has used net start and net use for system service discovery.

T1007
System Service Discovery
GroupMirrorFace

MirrorFace has used Tasklist for discovery post compromise.

T1007
System Service Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1007
System Service Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1008
Fallback Channels
GroupAPT41

APT41 used the Steam community page as a fallback mechanism for C2.

T1008
Fallback Channels
GroupFIN7

FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.

T1008
Fallback Channels
GroupUNC3886

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

T1008
Fallback Channels
GroupOilRig

OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP.

T1008
Fallback Channels
GroupLazarus Group

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

T1010
Application Window Discovery
GroupVolt Typhoon

Volt Typhoon has collected window title information from compromised systems.

T1010
Application Window Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground.

T1010
Application Window Discovery
GroupHEXANE

HEXANE has used a PowerShell-based keylogging tool to capture the window title.

T1012
Query Registry
GroupIndrik Spider

Indrik Spider has used a service account to extract copies of the `Security` Registry hive.

T1012
Query Registry
GroupBlackByte

BlackByte queried registry values to determine system language settings.

T1012
Query Registry
GroupKimsuky

Kimsuky has obtained specific Registry keys and values on a compromised host.

T1012
Query Registry
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1012
Query Registry
GroupAPT41

APT41 queried registry values to determine items such as configured RDP ports and network configurations.

T1012
Query Registry
GroupDragonfly

Dragonfly has queried the Registry to identify victim information.

T1012
Query Registry
GroupAPT32

APT32's backdoor can query the Windows Registry to gather system information.

T1012
Query Registry
GroupGamaredon Group

Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses. Gamaredon Group has queried ` HKEY_CURRENT_USER\\Console\\WindowsUpdates` to obtain the C2 addresses.

T1012
Query Registry
GroupZIRCONIUM

ZIRCONIUM has used a tool to query the Registry for proxy settings.

T1012
Query Registry
GroupAPT39

APT39 has used various strains of malware to query the Registry.

T1012
Query Registry
GroupOilRig

OilRig has used reg query “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” on a victim to query the Registry.

T1012
Query Registry
GroupTurla

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1012
Query Registry
GroupLotus Blossom

Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service.

T1012
Query Registry
GroupStealth Falcon

Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry.

T1012
Query Registry
GroupChimera

Chimera has queried Registry keys using reg query \\<host>\HKU\<SID>\SOFTWARE\Microsoft\Terminal Server Client\Servers and reg query \\<host>\HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Internet Settings.

T1012
Query Registry
GroupFox Kitten

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.