ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1046
Network Service Discovery
MalwarePysa

Pysa can perform network reconnaissance using the Advanced Port Scanner tool.

T1046
Network Service Discovery
MalwareMgBot

MgBot includes modules for performing HTTP and server service scans.

T1046
Network Service Discovery
MalwareSpeakUp

SpeakUp checks for availability of specific ports on servers.

T1046
Network Service Discovery
MalwareCobalt Strike

Cobalt Strike can perform port scans from an infected host.

T1046
Network Service Discovery
MalwareRamsay

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.

T1046
Network Service Discovery
MalwareZxShell

ZxShell can launch port scans.

T1046
Network Service Discovery
MalwareIndustroyer

Industroyer uses a custom port scanner to map out a network.

T1046
Network Service Discovery
MalwareHermeticWizard

HermeticWizard has the ability to scan ports on a compromised network.

T1046
Network Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can scan for open ports on a compromised machine.

T1046
Network Service Discovery
ToolEmpire

Empire can perform port scans from an infected host.

T1046
Network Service Discovery
ToolFRP

As part of load balancing FRP can set `healthCheck.type = "tcp"` or `healthCheck.type = "http"` to check service status on specific hosts with TCPing or an HTTP request.

T1046
Network Service Discovery
ToolPoshC2

PoshC2 can perform port scans from an infected host.

T1046
Network Service Discovery
ToolBrute Ratel C4

Brute Ratel C4 can conduct port scanning against targeted systems.

T1046
Network Service Discovery
ToolPeirates

Peirates can initiate a port scan against a given IP address.

T1046
Network Service Discovery
ToolNBTscan

NBTscan can be used to scan IP networks.

T1046
Network Service Discovery
ToolKoadic

Koadic can scan for open TCP ports on the target network.

T1046
Network Service Discovery
ToolPupy

Pupy has a built-in module for port scanning.

T1047
Windows Management Instrumentation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.

T1047
Windows Management Instrumentation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used WMI for execution.

T1047
Windows Management Instrumentation
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1047
Windows Management Instrumentation
CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1047
Windows Management Instrumentation
CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1047
Windows Management Instrumentation
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1047
Windows Management Instrumentation
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

T1047
Windows Management Instrumentation
CampaignFunnyDream

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

T1047
Windows Management Instrumentation
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys.

T1047
Windows Management Instrumentation
CampaignOperation Wocao

During Operation Wocao, threat actors has used WMI to execute commands.

T1047
Windows Management Instrumentation
CampaignC0027

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

T1047
Windows Management Instrumentation
GroupIndrik Spider

Indrik Spider has used WMIC to execute commands on remote computers.

T1047
Windows Management Instrumentation
GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1047
Windows Management Instrumentation
GroupGALLIUM

GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1047
Windows Management Instrumentation
GroupAPT32

APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1047
Windows Management Instrumentation
GroupNaikon

Naikon has used WMIC.exe for lateral movement.

T1047
Windows Management Instrumentation
GroupFIN6

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1047
Windows Management Instrumentation
GroupFIN7

FIN7 has used WMI to install malware on targeted systems.

T1047
Windows Management Instrumentation
GroupSandworm Team

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1047
Windows Management Instrumentation
GroupTA2541

TA2541 has used WMI to query targeted systems for security products.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1047
Windows Management Instrumentation
GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

T1047
Windows Management Instrumentation
GroupLeviathan

Leviathan has used WMI for execution.

T1047
Windows Management Instrumentation
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe to set environment variables.

T1047
Windows Management Instrumentation
GroupLotus Blossom

Lotus Blossom has used WMI to enable lateral movement.

T1047
Windows Management Instrumentation
GroupStealth Falcon

Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.