ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1049
System Network Connections Discovery
ToolFRP

FRP can use a dashboard and U/I to display the status of connections from the FRP client and server.

T1049
System Network Connections Discovery
Toolnetstat

netstat can be used to enumerate local network connections, including active TCP connections and other network statistics.

T1049
System Network Connections Discovery
ToolPoshC2

PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections.

T1049
System Network Connections Discovery
Toolnbtstat

nbtstat can be used to discover current NetBIOS sessions.

T1049
System Network Connections Discovery
ToolCrackMapExec

CrackMapExec can discover active sessions for a targeted system.

T1049
System Network Connections Discovery
ToolPupy

Pupy has a built-in utility command for netstat, can do net session through PowerView, and has an interactive shell which can be used to discover additional information.

T1049
System Network Connections Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord.

T1049
System Network Connections Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on network connections.

T1052.001
Exfiltration over USB
MalwareMachete

Machete has a feature to copy files from every drive onto a removable drive in a hidden folder.

T1052.001
Exfiltration over USB
MalwareAgent.btz

Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs.

T1052.001
Exfiltration over USB
MalwareRemsec

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

T1052.001
Exfiltration over USB
MalwareSPACESHIP

SPACESHIP copies staged data to removable drives when they are inserted into the system.

T1052.001
Exfiltration over USB
MalwareUSBStealer

USBStealer exfiltrates collected files via removable media from air-gapped victims.

T1053
Scheduled Task/Job
MalwareLokibot

Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution.

T1053.002
At
MalwareMURKYTOP

MURKYTOP has the capability to schedule remote AT jobs.

T1053.002
At
Toolat

at can be used to schedule a task on a system to be executed at a specific date or time.

T1053.002
At
ToolCrackMapExec

CrackMapExec can set a scheduled task on the target system to execute commands remotely using at.

T1053.003
Cron
MalwareExaramel for Linux

Exaramel for Linux uses crontab for persistence if it does not have root privileges.

T1053.003
Cron
MalwareJanicab

Janicab used a cron job for persistence on Mac devices.

T1053.003
Cron
MalwareNETWIRE

NETWIRE can use crontabs to establish persistence.

T1053.003
Cron
MalwareGomir

Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges.

T1053.003
Cron
MalwareSkidmap

Skidmap has installed itself via crontab.

T1053.003
Cron
MalwareGoldMax

The GoldMax Linux variant has used a crontab entry with a @reboot line to gain persistence.

T1053.003
Cron
MalwareAnchor

Anchor can install itself as a cron job.

T1053.003
Cron
MalwareXbash

Xbash can create a cronjob for persistence if it determines it is on a Linux system.

T1053.003
Cron
MalwareSpeakUp

SpeakUp uses cron tasks to ensure persistence.

T1053.003
Cron
MalwareNKAbuse

NKAbuse uses a Cron job to establish persistence when infecting Linux hosts.

T1053.003
Cron
MalwarePenquin

Penquin can use Cron to create periodic and pre-scheduled background jobs.

T1053.003
Cron
MalwareKinsing

Kinsing has used crontab to download and run shell scripts every minute to ensure persistence.

T1053.005
Scheduled Task
MalwareTrickBot

TrickBot creates a scheduled task on the system that provides persistence.

T1053.005
Scheduled Task
MalwareBumblebee

Bumblebee can achieve persistence by copying its DLL to a subdirectory of %APPDATA% and creating a Visual Basic Script that will load the DLL via a scheduled task.

T1053.005
Scheduled Task
MalwareGRIFFON

GRIFFON has used sctasks for persistence.

T1053.005
Scheduled Task
Malwareyty

yty establishes persistence by creating a scheduled task with the command SchTasks /Create /SC DAILY /TN BigData /TR “ + path_file + “/ST 09:30“.

T1053.005
Scheduled Task
MalwareStuxnet

Stuxnet schedules a network job to execute two minutes after host infection.

T1053.005
Scheduled Task
MalwarePOWRUNER

POWRUNER persists through a scheduled task that executes it every minute.

T1053.005
Scheduled Task
MalwareSharpStage

SharpStage has a persistence component to write a scheduled task for the payload.

T1053.005
Scheduled Task
MalwareSmoke Loader

Smoke Loader launches a scheduled task.

T1053.005
Scheduled Task
MalwareMatryoshka

Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization".

T1053.005
Scheduled Task
MalwareGravityRAT

GravityRAT creates a scheduled task to ensure it is re-executed everyday.

T1053.005
Scheduled Task
MalwarePrestige

Prestige has been executed on a target system through a scheduled task created by Sandworm Team using Impacket.

T1053.005
Scheduled Task
MalwareSharpDisco

SharpDisco can create scheduled tasks to execute reverse shells that read and write data to and from specified SMB shares.

T1053.005
Scheduled Task
MalwareTONESHELL

TONESHELL has created scheduled tasks to maintain persistence.

T1053.005
Scheduled Task
MalwareRainyDay

RainyDay can use scheduled tasks to achieve persistence.

T1053.005
Scheduled Task
MalwareNETWIRE

NETWIRE can create a scheduled task to establish persistence.

T1053.005
Scheduled Task
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file creates a scheduled task to launch a malicious executable.

T1053.005
Scheduled Task
MalwareCosmicDuke

CosmicDuke uses scheduled tasks typically named "Watchmon Service" for persistence.

T1053.005
Scheduled Task
MalwareIMAPLoader

IMAPLoader creates scheduled tasks for persistence based on the operating system version of the victim machine.

T1053.005
Scheduled Task
MalwareEmotet

Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry.

T1053.005
Scheduled Task
MalwareTomiris

Tomiris has used `SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00` to establish persistence.

T1053.005
Scheduled Task
MalwareBADHATCH

BADHATCH can use `schtasks.exe` to gain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.