ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1222.001×

10 examples

TechniqueUsed byProcedure example
T1222.001
Windows Permissions
MalwareWastedLocker

WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.

T1222.001
Windows Permissions
MalwareBlackCat

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

T1222.001
Windows Permissions
MalwareWannaCry

WannaCry uses attrib +h and icacls . /grant Everyone:F /T /C /Q to make some of its files hidden and grant all users full access controls.

T1222.001
Windows Permissions
MalwareBlackByte Ransomware

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

T1222.001
Windows Permissions
MalwareGrandoreiro

Grandoreiro can modify the binary ACL to prevent security tools from running.

T1222.001
Windows Permissions
MalwareRyuk

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

T1222.001
Windows Permissions
MalwareCaddyWiper

CaddyWiper can modify ACL entries to take ownership of files.

T1222.001
Windows Permissions
MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

T1222.001
Windows Permissions
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1222.001
Windows Permissions
ToolDiskpart

Diskpart can be used to display, set, or clear attributes of a disk or volume.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.