ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareBlackCat

BlackCat can utilize `net use` commands to discover the user name on a compromised host.

T1033
System Owner/User Discovery
MalwareVERMIN

VERMIN gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareNightdoor

Nightdoor gathers information on victim system users and usernames.

T1033
System Owner/User Discovery
MalwareMarkiRAT

MarkiRAT can retrieve the victim’s username.

T1033
System Owner/User Discovery
MalwarePowerShower

PowerShower has the ability to identify the current user on the infected host.

T1033
System Owner/User Discovery
MalwareKazuar

Kazuar gathers information on users.

T1033
System Owner/User Discovery
MalwareDarkComet

DarkComet gathers the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure.

T1033
System Owner/User Discovery
MalwareLucifer

Lucifer has the ability to identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwarezwShell

zwShell can obtain the name of the logged-in user on the victim.

T1033
System Owner/User Discovery
MalwareDRATzarus

DRATzarus can obtain a list of users from an infected machine.

T1033
System Owner/User Discovery
MalwareRising Sun

Rising Sun can detect the username of the infected host.

T1033
System Owner/User Discovery
MalwareChrommme

Chrommme can retrieve the username from a targeted system.

T1033
System Owner/User Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted usernames on infected endpoints.

T1033
System Owner/User Discovery
MalwareSocGholish

SocGholish can use `whoami` to obtain the username from a compromised host.

T1033
System Owner/User Discovery
MalwareFlagpro

Flagpro has been used to run the whoami command on the system.

T1033
System Owner/User Discovery
MalwareXAgentOSX

XAgentOSX contains the getInfoOSX function to return the OS X version as well as the current user.

T1033
System Owner/User Discovery
MalwareROKRAT

ROKRAT can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareDarkWatchman

DarkWatchman has collected the username from a victim machine.

T1033
System Owner/User Discovery
MalwareDyre

Dyre has the ability to identify the users on a compromised host.

T1033
System Owner/User Discovery
MalwarePlugX

PlugX has the ability to gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareReaver

Reaver collects the victim's username.

T1033
System Owner/User Discovery
MalwareS-Type

S-Type has run tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareRemsec

Remsec can obtain information about the current user.

T1033
System Owner/User Discovery
MalwareExplosive

Explosive has collected the username from the infected host.

T1033
System Owner/User Discovery
MalwareEpic

Epic collects the user name from the victim’s machine.

T1033
System Owner/User Discovery
MalwareClambling

Clambling can identify the username on a compromised host.

T1033
System Owner/User Discovery
MalwarePureCrypter

PureCrypter can retrieve the username from targeted machines.

T1033
System Owner/User Discovery
MalwareNanHaiShu

NanHaiShu collects the username from the victim.

T1033
System Owner/User Discovery
MalwareSVCReady

SVCReady can collect the username from an infected host.

T1033
System Owner/User Discovery
MalwareNGLite

NGLite will run the whoami command to gather system information and return this to the command and control server.

T1033
System Owner/User Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of user accounts from a victim's machine.

T1033
System Owner/User Discovery
MalwareGazer

Gazer obtains the current user's security identifier.

T1033
System Owner/User Discovery
MalwareLatrodectus

Latrodectus can discover the username of an infected host.

T1033
System Owner/User Discovery
MalwareSaint Bot

Saint Bot can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareChaes

Chaes has collected the username and UID from the infected machine.

T1033
System Owner/User Discovery
MalwareLODEINFO

LODEINFO can identify the associated username on targeted machines.

T1033
System Owner/User Discovery
MalwareEVILNUM

EVILNUM can obtain the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareSMOKEDHAM

SMOKEDHAM has used whoami commands to identify system owners.

T1033
System Owner/User Discovery
MalwareQUADAGENT

QUADAGENT gathers the victim username.

T1033
System Owner/User Discovery
MalwareSys10

Sys10 collects the account name of the logged-in user and sends it to the C2.

T1033
System Owner/User Discovery
MalwareMetamorfo

Metamorfo has collected the username from the victim's machine.

T1033
System Owner/User Discovery
MalwareTrojan.Karagany

Trojan.Karagany can gather information about the user on a compromised host.

T1033
System Owner/User Discovery
MalwareKONNI

KONNI can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareT9000

T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM.

T1033
System Owner/User Discovery
MalwareDnsSystem

DnsSystem can use the Windows user name to create a unique identification for infected users and systems.

T1033
System Owner/User Discovery
MalwareBLUELIGHT

BLUELIGHT can collect the username on a compromised host.

T1033
System Owner/User Discovery
MalwareIxeshe

Ixeshe collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareMicropsia

Micropsia collects the username from the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.