ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareBabyShark

BabyShark has executed the whoami command.

T1033
System Owner/User Discovery
MalwareCannon

Cannon can gather the username from the system.

T1033
System Owner/User Discovery
MalwareCreepySnail

CreepySnail can execute `getUsername` on compromised systems.

T1033
System Owner/User Discovery
MalwarenjRAT

njRAT enumerates the current user during the initial infection.

T1033
System Owner/User Discovery
MalwareJPIN

JPIN can obtain the victim user name.

T1033
System Owner/User Discovery
MalwaremetaMain

metaMain can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareSideTwist

SideTwist can collect the username on a targeted system.

T1033
System Owner/User Discovery
MalwareMechaFlounder

MechaFlounder has the ability to identify the username and hostname on a compromised host.

T1033
System Owner/User Discovery
MalwareMis-Type

Mis-Type runs tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareLunarWeb

LunarWeb can collect user information from the targeted host.

T1033
System Owner/User Discovery
MalwareOctopus

Octopus can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareSTARWHALE

STARWHALE can gather the username from an infected host.

T1033
System Owner/User Discovery
MalwareMirageFox

MirageFox can gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareDownPaper

DownPaper collects the victim username and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwarePOWERSTATS

POWERSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name.

T1033
System Owner/User Discovery
MalwareShadowPad

ShadowPad has collected the username of the victim system.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1033
System Owner/User Discovery
MalwareGelsemium

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1033
System Owner/User Discovery
MalwareKomplex

The OsInfo function in Komplex collects the current running username.

T1033
System Owner/User Discovery
MalwareDenis

Denis enumerates and collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareLizar

Lizar can collect the username from the system.

T1033
System Owner/User Discovery
MalwareAzorult

Azorult can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareUPPERCUT

UPPERCUT has the capability to collect the current logged on user’s username from a machine.

T1033
System Owner/User Discovery
MalwareStrifeWater

StrifeWater can collect the user name from the victim's machine.

T1033
System Owner/User Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected the username from a victim machine.

T1033
System Owner/User Discovery
MalwareXORIndex Loader

XORIndex Loader has collected the username from the victim host.

T1033
System Owner/User Discovery
MalwareSmall Sieve

Small Sieve can obtain the id of a logged in user.

T1033
System Owner/User Discovery
ToolBloodHound

BloodHound can collect information on user sessions.

T1033
System Owner/User Discovery
ToolSILENTTRINITY

SILENTTRINITY can gather a list of logged on users.

T1033
System Owner/User Discovery
ToolEmpire

Empire can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolAsyncRAT

AsyncRAT can check if the current user of a compromised system is an administrator.

T1033
System Owner/User Discovery
ToolRemcos

Remcos can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolNBTscan

NBTscan can list active users on the system.

T1033
System Owner/User Discovery
ToolKoadic

Koadic can identify logged in users across the domain and views user sessions.

T1033
System Owner/User Discovery
ToolPupy

Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts.

T1033
System Owner/User Discovery
ToolQuasarRAT

QuasarRAT can enumerate the username and account type.

T1033
System Owner/User Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user.

T1033
System Owner/User Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner.

T1033
System Owner/User Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

T1036
Masquerading
CampaignKV Botnet Activity

KV Botnet Activity involves changing process filename to pr_set_mm_exe_file and process name to pr_set_name during later infection stages.

T1036
Masquerading
CampaignOperation Honeybee

During Operation Honeybee, the threat actors modified the MaoCheng dropper so its icon appeared as a Word document.

T1036
Masquerading
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

T1036
Masquerading
CampaignC0018

During C0018, AvosLocker was disguised using the victim company name as the filename.

T1036
Masquerading
CampaignC0015

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

T1036
Masquerading
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors used voice calls to socially engineer victims into authorizing a modified version of the Salesforce Data Loader app.

T1036
Masquerading
CampaignArcaneDoor

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

T1036
Masquerading
GroupmenuPass

menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files.

T1036
Masquerading
GroupAPT32

APT32 has disguised a Cobalt Strike beacon as a Flash Installer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.