ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareLucifer

Lucifer can use WMI to log into remote machines for propagation.

T1047
Windows Management Instrumentation
MalwareBlackEnergy

A BlackEnergy 2 plug-in uses WMI to gather victim host details.

T1047
Windows Management Instrumentation
MalwareNotPetya

NotPetya can use wmic to help propagate itself across a network.

T1047
Windows Management Instrumentation
MalwareAvaddon

Avaddon uses wmic.exe to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareSocGholish

SocGholish has used WMI calls for script execution and system profiling.

T1047
Windows Management Instrumentation
MalwareHELLOKITTY

HELLOKITTY can use WMI to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareDarkTortilla

DarkTortilla can use WMI queries to obtain system information.

T1047
Windows Management Instrumentation
MalwareDarkWatchman

DarkWatchman can use WMI to execute commands.

T1047
Windows Management Instrumentation
MalwareDustySky

The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active.

T1047
Windows Management Instrumentation
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use WMI to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareAkira

Akira will leverage COM objects accessed through WMI during execution to evade detection.

T1047
Windows Management Instrumentation
MalwareDarkGate

DarkGate has used WMI to execute files over the network and to obtain information about the domain.

T1047
Windows Management Instrumentation
MalwareSVCReady

SVCReady can use `WMI` queries to detect the presence of a virtual machine environment.

T1047
Windows Management Instrumentation
MalwareNetwalker

Netwalker can use WMI to delete Shadow Volumes.

T1047
Windows Management Instrumentation
MalwareWannaCry

WannaCry utilizes wmic to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareLatrodectus

Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files.

T1047
Windows Management Instrumentation
MalwareLODEINFO

LODEINFO can execute commands with WMI.

T1047
Windows Management Instrumentation
MalwareCharmPower

CharmPower can use `wmic` to gather information from a system.

T1047
Windows Management Instrumentation
MalwareEVILNUM

EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines.

T1047
Windows Management Instrumentation
MalwareKOMPROGO

KOMPROGO is capable of running WMI queries.

T1047
Windows Management Instrumentation
MalwareMoleNet

MoleNet can perform WMI commands on the system.

T1047
Windows Management Instrumentation
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

T1047
Windows Management Instrumentation
MalwareBlack Basta

Black Basta has used WMI to execute files over the network.

T1047
Windows Management Instrumentation
MalwareStoneDrill

StoneDrill has used the WMI command-line (WMIC) utility to run tasks.

T1047
Windows Management Instrumentation
MalwareOopsIE

OopsIE uses WMI to perform discovery techniques.

T1047
Windows Management Instrumentation
MalwareRogueRobin

RogueRobin uses various WMI queries to check if the sample is running in a sandbox.

T1047
Windows Management Instrumentation
MalwareMosquito

Mosquito's installer uses WMI to search for antivirus display names.

T1047
Windows Management Instrumentation
MalwareSibot

Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL.

T1047
Windows Management Instrumentation
MalwareBazar

Bazar can execute a WMI query to gather information about the installed antivirus engine.

T1047
Windows Management Instrumentation
MalwareRATANKBA

RATANKBA uses WMI to perform process monitoring.

T1047
Windows Management Instrumentation
MalwareLockBit 2.0

LockBit 2.0 can use wmic.exe to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareZebrocy

One variant of Zebrocy uses WMI queries to gather information.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
MalwareSUNBURST

SUNBURST used the WMI query Select * From Win32_SystemDriver to retrieve a driver listing.

T1047
Windows Management Instrumentation
MalwareEvilBunny

EvilBunny has used WMI to gather information about the system.

T1047
Windows Management Instrumentation
MalwareREvil

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1047
Windows Management Instrumentation
MalwareValak

Valak can use wmic process call create in a scheduled task to launch plugins and for execution.

T1047
Windows Management Instrumentation
MalwareAshTag

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

T1047
Windows Management Instrumentation
MalwareFunnyDream

FunnyDream can use WMI to open a Windows command shell on a remote machine.

T1047
Windows Management Instrumentation
MalwareSysUpdate

SysUpdate can use WMI for execution on a compromised host.

T1047
Windows Management Instrumentation
MalwareLAMEHUG

LAMEHUG can use wmic to collect system information.

T1047
Windows Management Instrumentation
MalwareFELIXROOT

FELIXROOT uses WMI to query the Windows Registry.

T1047
Windows Management Instrumentation
MalwareMeteor

Meteor can use `wmic.exe` as part of its effort to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareMaze

Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network.

T1047
Windows Management Instrumentation
MalwareLunarWeb

LunarWeb can use WMI queries for discovery on the victim host.

T1047
Windows Management Instrumentation
MalwareOctopus

Octopus has used wmic.exe for local discovery information.

T1047
Windows Management Instrumentation
MalwareQilin

Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.

T1047
Windows Management Instrumentation
MalwareAgent Tesla

Agent Tesla has used wmi queries to gather information from the system.

T1047
Windows Management Instrumentation
MalwarePOWERSTATS

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1047
Windows Management Instrumentation
MalwareRemexi

Remexi executes received commands with wmic.exe (for WMI commands).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.