ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S1199×

26 examples

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareLockBit 2.0

LockBit 2.0 has the ability to move laterally via SMB.

T1047
Windows Management Instrumentation
MalwareLockBit 2.0

LockBit 2.0 can use wmic.exe to delete volume shadow copies.

T1053.005
Scheduled Task
MalwareLockBit 2.0

LockBit 2.0 can be executed via scheduled task.

T1057
Process Discovery
MalwareLockBit 2.0

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1059.001
PowerShell
MalwareLockBit 2.0

LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1070.004
File Deletion
MalwareLockBit 2.0

LockBit 2.0 can delete itself from disk after execution.

T1082
System Information Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate system information including hostname and domain information.

T1083
File and Directory Discovery
MalwareLockBit 2.0

LockBit 2.0 can exclude files associated with core system functions from encryption.

T1112
Modify Registry
MalwareLockBit 2.0

LockBit 2.0 can create Registry keys to bypass UAC and for persistence.

T1120
Peripheral Device Discovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to identify mounted external storage devices.

T1135
Network Share Discovery
MalwareLockBit 2.0

LockBit 2.0 can discover remote shares.

T1136
Create Account
MalwareLockBit 2.0

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 2.0

LockBit 2.0 can decode scripts and strings in loaded modules.

T1480
Execution Guardrails
MalwareLockBit 2.0

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

T1484.001
Group Policy Modification
MalwareLockBit 2.0

LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains.

T1486
Data Encrypted for Impact
MalwareLockBit 2.0

LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data.

T1489
Service Stop
MalwareLockBit 2.0

LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes.

T1490
Inhibit System Recovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwareLockBit 2.0

LockBit 2.0 can use a Registry Run key to establish persistence at startup.

T1548.002
Bypass User Account Control
MalwareLockBit 2.0

LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`.

T1564.003
Hidden Window
MalwareLockBit 2.0

LockBit 2.0 can execute command line arguments in a hidden window.

T1614.001
System Language Discovery
MalwareLockBit 2.0

LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1685
Disable or Modify Tools
MalwareLockBit 2.0

LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.