ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareBlackEnergy

BlackEnergy has run a keylogger plug-in on a victim.

T1056.001
Keylogging
MalwareXAgentOSX

XAgentOSX contains keylogging functionality that will monitor for active application windows and write them to the log, it can handle special characters, and it will buffer by default 50 characters before sending them out over the C2 infrastructure.

T1056.001
Keylogging
MalwareKeyBoy

KeyBoy installs a keylogger for intercepting credentials and keystrokes.

T1056.001
Keylogging
MalwareDarkTortilla

DarkTortilla can download a keylogging module.

T1056.001
Keylogging
MalwareROKRAT

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1056.001
Keylogging
MalwareRunningRAT

RunningRAT captures keystrokes and sends them back to the C2 server.

T1056.001
Keylogging
MalwareDarkWatchman

DarkWatchman can track key presses with a keylogger module.

T1056.001
Keylogging
MalwarePlugX

PlugX has a module for capturing keystrokes per process including window titles.

T1056.001
Keylogging
MalwareDustySky

DustySky contains a keylogger.

T1056.001
Keylogging
MalwareRemsec

Remsec contains a keylogger component.

T1056.001
Keylogging
MalwareSykipot

Sykipot contains keylogging functionality to steal passwords.

T1056.001
Keylogging
MalwareExplosive

Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers.

T1056.001
Keylogging
MalwareRover

Rover has keylogging functionality.

T1056.001
Keylogging
MalwarePeppy

Peppy can log keystrokes on compromised hosts.

T1056.001
Keylogging
MalwareCuba

Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.

T1056.001
Keylogging
MalwareClambling

Clambling can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareDarkGate

DarkGate will spawn a thread on execution to capture all keyboard events and write them to a predefined log file.

T1056.001
Keylogging
MalwareThiefQuest

ThiefQuest uses the CGEventTap functions to perform keylogging.

T1056.001
Keylogging
MalwareCarbanak

Carbanak logs key strokes for configured processes and sends them back to the C2 server.

T1056.001
Keylogging
MalwareLODEINFO

LODEINFO can capture keystrokes on targeted systems.

T1056.001
Keylogging
MalwareSMOKEDHAM

SMOKEDHAM can continuously capture keystrokes.

T1056.001
Keylogging
MalwareMetamorfo

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareTrojan.Karagany

Trojan.Karagany can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwareBandook

Bandook contains keylogging capabilities.

T1056.001
Keylogging
MalwareKONNI

KONNI has the capability to perform keylogging.

T1056.001
Keylogging
Malwaregh0st RAT

gh0st RAT has a keylogger.

T1056.001
Keylogging
MalwareKGH_SPY

KGH_SPY can perform keylogging by polling the GetAsyncKeyState() function.

T1056.001
Keylogging
MalwareMicropsia

Micropsia has keylogging capabilities.

T1056.001
Keylogging
MalwareCatchamas

Catchamas collects keystrokes from the victim’s machine.

T1056.001
Keylogging
MalwareAttor

One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process.

T1056.001
Keylogging
MalwareNightClub

NightClub can use a plugin for keylogging.

T1056.001
Keylogging
MalwareRTM

RTM can record keystrokes from both the keyboard and virtual keyboard.

T1056.001
Keylogging
MalwareDerusbi

Derusbi is capable of logging keystrokes.

T1056.001
Keylogging
MalwareGrandoreiro

Grandoreiro can log keystrokes on the victim's machine.

T1056.001
Keylogging
MalwareBadPatch

BadPatch has a keylogging capability.

T1056.001
Keylogging
MalwareXLoader

XLoader can capture keystrokes from the victim machine.

T1056.001
Keylogging
MalwareMoonWind

MoonWind has a keylogger.

T1056.001
Keylogging
MalwareCorKLOG

CorKLOG has captured keystrokes.

T1056.001
Keylogging
MalwareMgBot

MgBot includes keylogger payloads focused on the QQ chat application.

T1056.001
Keylogging
MalwareOwaAuth

OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, C:\log.txt.

T1056.001
Keylogging
MalwareCadelspy

Cadelspy has the ability to log keystrokes on the compromised host.

T1056.001
Keylogging
MalwareCobalt Strike

Cobalt Strike can track key presses with a keylogger module.

T1056.001
Keylogging
MalwareCobian RAT

Cobian RAT has a feature to perform keylogging on the victim’s machine.

T1056.001
Keylogging
MalwareUnknown Logger

Unknown Logger is capable of recording keystrokes.

T1056.001
Keylogging
MalwareKivars

Kivars has the ability to initiate keylogging on the infected host.

T1056.001
Keylogging
MalwarePoisonIvy

PoisonIvy contains a keylogger.

T1056.001
Keylogging
MalwareNanoCore

NanoCore can perform keylogging on the victim’s machine.

T1056.001
Keylogging
MalwareTajMahal

TajMahal has the ability to capture keystrokes on an infected host.

T1056.001
Keylogging
MalwareDaserf

Daserf can log keystrokes.

T1056.001
Keylogging
MalwareCardinal RAT

Cardinal RAT can log keystrokes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.