ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1134.002×

11 examples

TechniqueUsed byProcedure example
T1134.002
Create Process with Token
MalwareBankshot

Bankshot grabs a user token using WTSQueryUserToken and then creates a process by impersonating a logged-on user.

T1134.002
Create Process with Token
MalwareTONESHELL

TONESHELL included functionality to create sub-processes with a specific user’s token.

T1134.002
Create Process with Token
MalwareAria-body

Aria-body has the ability to execute a process using runas.

T1134.002
Create Process with Token
MalwareWhisperGate

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.

T1134.002
Create Process with Token
MalwarePipeMon

PipeMon can attempt to gain administrative privileges using token impersonation.

T1134.002
Create Process with Token
MalwareKONNI

KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.

T1134.002
Create Process with Token
MalwareREvil

REvil can launch an instance of itself with administrative rights using runas.

T1134.002
Create Process with Token
MalwareZxShell

ZxShell has a command called RunAs, which creates a new process as another user or process context.

T1134.002
Create Process with Token
MalwareAzorult

Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges.

T1134.002
Create Process with Token
ToolEmpire

Empire can use Invoke-RunAs to make tokens.

T1134.002
Create Process with Token
ToolPoshC2

PoshC2 can use Invoke-RunAs to make tokens.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.