ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareGelsemium

Gelsemium can use multiple domains and protocols in C2.

T1008
Fallback Channels
ToolMythic

Mythic can use a list of C2 URLs as fallback mechanisms in case one IP or domain gets blocked.

T1008
Fallback Channels
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset.

T1008
Fallback Channels
MalwareMini Shai-Hulud

Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable.

T1010
Application Window Discovery
MalwarePowerDuke

PowerDuke has a command to get text of the current foreground window.

T1010
Application Window Discovery
MalwarePAKLOG

PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows.

T1010
Application Window Discovery
MalwareTONESHELL

TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1010
Application Window Discovery
MalwareNETWIRE

NETWIRE can discover and close windows on controlled systems.

T1010
Application Window Discovery
MalwareAria-body

Aria-body has the ability to identify the titles of running windows on a compromised host.

T1010
Application Window Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running application windows.

T1010
Application Window Discovery
MalwareMachete

Machete saves the window names.

T1010
Application Window Discovery
MalwareInvisiMole

InvisiMole can enumerate windows and child windows on a compromised host.

T1010
Application Window Discovery
MalwareWINERACK

WINERACK can enumerate active windows.

T1010
Application Window Discovery
MalwareKazuar

Kazuar gathers information about opened windows.

T1010
Application Window Discovery
MalwareFlagpro

Flagpro can check the name of the window displayed on the system.

T1010
Application Window Discovery
MalwareROKRAT

ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing.

T1010
Application Window Discovery
MalwareDarkWatchman

DarkWatchman reports window names along with keylogger information to provide application context.

T1010
Application Window Discovery
MalwareDarkGate

DarkGate will search for cryptocurrency wallets by examining application window names for specific strings. DarkGate extracts information collected via NirSoft tools from the hosting process's memory by first identifying the window through the FindWindow API function.

T1010
Application Window Discovery
MalwareMetamorfo

Metamorfo can enumerate all windows on the victim’s machine.

T1010
Application Window Discovery
MalwareTrojan.Karagany

Trojan.Karagany can monitor the titles of open windows to identify specific keywords.

T1010
Application Window Discovery
MalwareCatchamas

Catchamas obtains application windows titles and then determines which windows to perform Screen Capture on.

T1010
Application Window Discovery
MalwareAttor

Attor can obtain application window titles and then determines which windows to perform Screen Capture on.

T1010
Application Window Discovery
MalwareNightClub

NightClub can use `GetForegroundWindow` to enumerate the active window.

T1010
Application Window Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on window names.

T1010
Application Window Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of enumerating application windows.

T1010
Application Window Discovery
MalwareCadelspy

Cadelspy has the ability to identify open windows on the compromised host.

T1010
Application Window Discovery
MalwareHotCroissant

HotCroissant has the ability to list the names of all open windows on the infected host.

T1010
Application Window Discovery
MalwarePoisonIvy

PoisonIvy captures window titles.

T1010
Application Window Discovery
MalwarePLEAD

PLEAD has the ability to list open windows on the compromised host.

T1010
Application Window Discovery
MalwareFunnyDream

FunnyDream has the ability to discover application windows via execution of `EnumWindows`.

T1010
Application Window Discovery
MalwareNetTraveler

NetTraveler reports window names along with keylogger information to provide application context.

T1010
Application Window Discovery
MalwarenjRAT

njRAT gathers information about opened windows during the initial infection.

T1010
Application Window Discovery
MalwareRemexi

Remexi has a command to capture active windows on the machine and retrieve window titles.

T1010
Application Window Discovery
MalwareQakBot

QakBot has the ability to enumerate windows on a compromised host.

T1010
Application Window Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`.

T1010
Application Window Discovery
ToolRemcos

Remcos can list all windows on victim systems.

T1010
Application Window Discovery
ToolQuasarRAT

APT-C-36 used a customized version of QuasarRAT to monitor browser windows for strings relating to specific Colombian financial institutions.

T1010
Application Window Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on open windows.

T1011.001
Exfiltration Over Bluetooth
MalwareFlame

Flame has a module named BeetleJuice that contains Bluetooth functionality that may be used in different ways, including transmitting encoded information from the infected system over the Bluetooth protocol, acting as a Bluetooth beacon, and identifying other Bluetooth devices in the vicinity.

T1012
Query Registry
MalwareSynAck

SynAck enumerates Registry keys associated with event logs.

T1012
Query Registry
MalwareBumblebee

Bumblebee can check the Registry for specific keys.

T1012
Query Registry
MalwareProxysvc

Proxysvc gathers product names from the Registry key: HKLM\Software\Microsoft\Windows NT\CurrentVersion ProductName and the processor description from the Registry key HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 ProcessorNameString.

T1012
Query Registry
MalwareStuxnet

Stuxnet searches the Registry for indicators of security programs.

T1012
Query Registry
MalwarePOWRUNER

POWRUNER may query the Registry by running reg query on a victim.

T1012
Query Registry
MalwareUrsnif

Ursnif has used Reg to query the Registry for installed programs.

T1012
Query Registry
MalwarePOWERSOURCE

POWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence.

T1012
Query Registry
MalwareZeus Panda

Zeus Panda checks for the existence of a Registry key and if it contains certain values.

T1012
Query Registry
MalwareBankshot

Bankshot searches for certain Registry keys to be configured before executing the payload.

T1012
Query Registry
MalwareBrave Prince

Brave Prince gathers information about the Registry.

T1012
Query Registry
MalwareTinyTurla

TinyTurla can query the Registry for its configuration information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.