ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1069.002
Domain Groups
MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1069.002
Domain Groups
MalwareKwampirs

Kwampirs collects a list of domain groups with the command net localgroup /domain.

T1069.002
Domain Groups
MalwareLAMEHUG

LAMEHUG can use dsquery to gather domain group information.

T1069.002
Domain Groups
MalwareEgregor

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1069.002
Domain Groups
MalwareQilin

Qilin can run PowerShell cmdlets to discover domain groups.

T1069.002
Domain Groups
MalwareSoreFang

SoreFang can enumerate domain groups by executing net.exe group /domain.

T1069.002
Domain Groups
MalwareHelminth

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1069.002
Domain Groups
MalwareOSInfo

OSInfo specifically looks for Domain Admins and power users within the domain.

T1069.002
Domain Groups
ToolNet

Commands such as net group /domain can be used in Net to gather information about and manipulate groups.

T1069.002
Domain Groups
ToolBloodHound

BloodHound can collect information about domain groups and members.

T1069.002
Domain Groups
ToolSILENTTRINITY

SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information.

T1069.002
Domain Groups
Tooldsquery

dsquery can be used to gather information on permission groups within a domain.

T1069.002
Domain Groups
ToolBrute Ratel C4

Brute Ratel C4 can use `net group` for discovery on targeted domains.

T1069.002
Domain Groups
ToolCrackMapExec

CrackMapExec can gather the user accounts within domain groups.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

T1069.003
Cloud Groups
ToolPacu

Pacu can enumerate IAM permissions.

T1069.003
Cloud Groups
ToolAADInternals

AADInternals can enumerate Azure AD groups.

T1069.003
Cloud Groups
ToolROADTools

ROADTools can enumerate Azure AD groups.

T1070
Indicator Removal
MalwareOrz

Orz can overwrite Registry settings to reduce its visibility on the victim.

T1070
Indicator Removal
MalwareStuxnet

Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads.

T1070
Indicator Removal
MalwareIronWind

IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems.

T1070
Indicator Removal
MalwareSardonic

Sardonic has the ability to delete created WMI objects to evade detections.

T1070
Indicator Removal
MalwareBankshot

Bankshot deletes all artifacts associated with the malware from the infected machine.

T1070
Indicator Removal
MalwareDUSTTRAP

DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed.

T1070
Indicator Removal
MalwareNeoichor

Neoichor can clear the browser history on a compromised host by changing the `ClearBrowsingHistoryOnExit` value to 1 in the `HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy` Registry key.

T1070
Indicator Removal
MalwareBlackEnergy

BlackEnergy has removed the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevant strings in the user32.dll.mui of the system.

T1070
Indicator Removal
MalwareRising Sun

Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.

T1070
Indicator Removal
MalwareFlagpro

Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections.

T1070
Indicator Removal
MalwareDarkWatchman

DarkWatchman can uninstall malicious components from the Registry, stop processes, and clear the browser history.

T1070
Indicator Removal
MalwareMultiLayer Wiper

MultiLayer Wiper uses a batch script to clear file system cache memory via the ProcessIdleTasks export in advapi32.dll as an anti-analysis and anti-forensics technique.

T1070
Indicator Removal
MalwareEVILNUM

EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack.

T1070
Indicator Removal
MalwareMetamorfo

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1070
Indicator Removal
MalwareBPFDoor

BPFDoor clears the file location `/proc/<PID>/environ` removing all environment variables for the process.

T1070
Indicator Removal
MalwareSDBbot

SDBbot has the ability to clean up and remove data structures from a compromised host.

T1070
Indicator Removal
MalwareSibot

Sibot will delete an associated registry key if a certain server response is received.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070
Indicator Removal
MalwareSUNBURST

SUNBURST removed HTTP proxy registry values to clean up traces of execution.

T1070
Indicator Removal
MalwareIPsec Helper

IPsec Helper can delete various registry keys related to its execution and use.

T1070
Indicator Removal
MalwareFunnyDream

FunnyDream has the ability to clean traces of malware deployment.

T1070
Indicator Removal
MalwareMaze

Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection.

T1070
Indicator Removal
MalwareShadowPad

ShadowPad has deleted arbitrary Registry values.

T1070
Indicator Removal
ToolSILENTTRINITY

SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys.

T1070
Indicator Removal
ToolCSPY Downloader

CSPY Downloader has the ability to remove values it writes to the Registry.

T1070
Indicator Removal
ToolRemcos

Remcos can clean saved cookies and logins from the web browser.

T1070
Indicator Removal
ToolDonut

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

T1070.003
Clear Command History
MalwareJ-magic

J-magic can overwrite previously executed command line arguments.

T1070.003
Clear Command History
MalwareHildegard

Hildegard has used history -c to clear script shell logs.

T1070.003
Clear Command History
MalwareKobalos

Kobalos can remove all command history on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.