ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1547.001×

201 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
MalwareROADSWEEP

ROADSWEEP has been placed in the start up folder to trigger execution upon user login.

T1547.001
Registry Run Keys / Startup Folder
MalwareSysUpdate

SysUpdate can use a Registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTinyZBot

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBoomBox

BoomBox can establish persistence by writing the Registry value MicroNativeCacheSvc to HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

T1547.001
Registry Run Keys / Startup Folder
MalwareInnaputRAT

Some InnaputRAT variants establish persistence by modifying the Registry key HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run:%appdata%\NeutralApp\NeutralApp.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrimAgent

GrimAgent can set persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareLookBack

LookBack sets up a Registry Run key to establish a persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoetRAT

PoetRAT has added a registry key in the <RUN> hive for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFELIXROOT

FELIXROOT adds a shortcut file to the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBabyShark

BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.

T1547.001
Registry Run Keys / Startup Folder
Malwarebuild_downer

build_downer has the ability to add itself to the Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareWinnti for Windows

Winnti for Windows can add a service named wind0ws to the Registry to achieve persistence after reboot.

T1547.001
Registry Run Keys / Startup Folder
MalwarenjRAT

njRAT has added persistence via the Registry key HKCU\Software\Microsoft\CurrentVersion\Run\ and dropped a shortcut in %STARTUP%.

T1547.001
Registry Run Keys / Startup Folder
MalwareMaze

Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHIUPAN

HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1547.001
Registry Run Keys / Startup Folder
MalwareTURNEDUP

TURNEDUP is capable of writing to a Registry Run key to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareChChes

ChChes establishes persistence by adding a Registry Run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareANDROMEDA

ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on.

T1547.001
Registry Run Keys / Startup Folder
MalwareKOCTOPUS

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

T1547.001
Registry Run Keys / Startup Folder
MalwareHeyoka Backdoor

Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1547.001
Registry Run Keys / Startup Folder
MalwareHTTPBrowser

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareOctopus

Octopus achieved persistence by placing a malicious executable in the startup directory and has added the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareQilin

Qilin has created a RunOnce autostart entry at `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce*aster = %Public%\enc.exe` pointing to a dropped copy of itself in the Public folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareSTARWHALE

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareDownPaper

DownPaper uses PowerShell to add a Registry Run key in order to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareCozyCar

One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

T1547.001
Registry Run Keys / Startup Folder
MalwareAgent Tesla

Agent Tesla can add itself to the Registry as a startup program to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwarePOWERTON

POWERTON can install a Registry Run key for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBADNEWS

BADNEWS installs a registry Run key to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareRemexi

Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareAstaroth

Astaroth creates a startup item for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHancitor

Hancitor has added Registry Run keys to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareGelsemium

Gelsemium can set persistence with a Registry run key.

T1547.001
Registry Run Keys / Startup Folder
MalwareHelminth

Helminth establishes persistence by creating a shortcut in the Start Menu folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareComnie

Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry.

T1547.001
Registry Run Keys / Startup Folder
MalwareVasport

Vasport copies itself to disk and creates an associated run key Registry entry to establish.

T1547.001
Registry Run Keys / Startup Folder
MalwareBitPaymer

BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBACKSPACE

BACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.

T1547.001
Registry Run Keys / Startup Folder
MalwareADVSTORESHELL

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareMivast

Mivast creates the following Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Micromedia.

T1547.001
Registry Run Keys / Startup Folder
MalwareWarzoneRAT

WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareSmall Sieve

Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolSILENTTRINITY

SILENTTRINITY can establish a LNK file in the startup folder for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolEmpire

Empire can modify the registry run keys HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolRemcos

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolMCMD

MCMD can use Registry Run Keys for persistence.

T1547.001
Registry Run Keys / Startup Folder
ToolKoadic

Koadic has added persistence to the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` Registry key.

T1547.001
Registry Run Keys / Startup Folder
ToolPupy

Pupy adds itself to the startup folder or adds itself to the Registry key SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.