ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1046
Network Service Discovery
MalwareXbash

Xbash can perform port scanning of TCP and UDP ports.

T1046
Network Service Discovery
MalwareXTunnel

XTunnel is capable of probing the network for open ports.

T1046
Network Service Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell has a module to use a port scanner on a system.

T1046
Network Service Discovery
MalwareRoyal

Royal can scan the network interfaces of targeted systems.

T1046
Network Service Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware identifies remote systems via active directory queries for hostnames prior to launching remote ransomware payloads.

T1046
Network Service Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced Port Scanner tool.

T1046
Network Service Discovery
MalwareMgBot

MgBot includes modules for performing HTTP and server service scans.

T1046
Network Service Discovery
MalwareSpeakUp

SpeakUp checks for availability of specific ports on servers.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1046
Network Service Discovery
MalwareRamsay

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.

T1046
Network Service Discovery
MalwareZxShell

ZxShell can launch port scans.

T1046
Network Service Discovery
MalwareIndustroyer

Industroyer uses a custom port scanner to map out a network.

T1046
Network Service Discovery
MalwareHermeticWizard

HermeticWizard has the ability to scan ports on a compromised network.

T1046
Network Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can scan for open ports on a compromised machine.

T1046
Network Service Discovery
ToolEmpire

Empire can perform port scans from an infected host.

T1046
Network Service Discovery
ToolFRP

As part of load balancing FRP can set `healthCheck.type = "tcp"` or `healthCheck.type = "http"` to check service status on specific hosts with TCPing or an HTTP request.

T1046
Network Service Discovery
ToolPoshC2

PoshC2 can perform port scans from an infected host.

T1046
Network Service Discovery
ToolBrute Ratel C4

Brute Ratel C4 can conduct port scanning against targeted systems.

T1046
Network Service Discovery
ToolPeirates

Peirates can initiate a port scan against a given IP address.

T1046
Network Service Discovery
ToolNBTscan

NBTscan can be used to scan IP networks.

T1046
Network Service Discovery
ToolKoadic

Koadic can scan for open TCP ports on the target network.

T1046
Network Service Discovery
ToolPupy

Pupy has a built-in module for port scanning.

T1047
Windows Management Instrumentation
MalwareEKANS

EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1047
Windows Management Instrumentation
MalwareStuxnet

Stuxnet used WMI with an explorer.exe token to execute on a remote share.

T1047
Windows Management Instrumentation
MalwarePOWRUNER

POWRUNER may use WMI when collecting information about a victim.

T1047
Windows Management Instrumentation
MalwareSharpStage

SharpStage can use WMI for execution.

T1047
Windows Management Instrumentation
MalwareSardonic

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1047
Windows Management Instrumentation
MalwareHALFBAKED

HALFBAKED can use WMI queries to gather system information.

T1047
Windows Management Instrumentation
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
MalwareUrsnif

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1047
Windows Management Instrumentation
MalwareGravityRAT

GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed).

T1047
Windows Management Instrumentation
MalwareROAMINGHOUSE

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1047
Windows Management Instrumentation
MalwareTONESHELL

TONESHELL has used WMI queries to gather information from the system.

T1047
Windows Management Instrumentation
MalwarePyDCrypt

PyDCrypt has attempted to execute with WMIC.

T1047
Windows Management Instrumentation
MalwareIMAPLoader

IMAPLoader uses WMI queries to query system information on victim hosts.

T1047
Windows Management Instrumentation
MalwareEmotet

Emotet has used WMI to execute powershell.exe.

T1047
Windows Management Instrumentation
MalwareOlympic Destroyer

Olympic Destroyer uses WMI to help propagate itself across a network.

T1047
Windows Management Instrumentation
MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1047
Windows Management Instrumentation
MalwareAction RAT

Action RAT can use WMI to gather AV products installed on an infected host.

T1047
Windows Management Instrumentation
MalwarePUBLOAD

PUBLOAD has used `wmic` to gather information from the victim device.

T1047
Windows Management Instrumentation
MalwareShrinkLocker

ShrinkLocker uses WMI to query information about the victim operating system.

T1047
Windows Management Instrumentation
MalwareFlawedAmmyy

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1047
Windows Management Instrumentation
MalwareSnip3

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1047
Windows Management Instrumentation
MalwareHOPLIGHT

HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository.

T1047
Windows Management Instrumentation
MalwareProLock

ProLock can use WMIC to execute scripts on targeted hosts.

T1047
Windows Management Instrumentation
MalwareRaspberry Robin

Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package.

T1047
Windows Management Instrumentation
MalwareBlackCat

BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.

T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1047
Windows Management Instrumentation
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.