ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1480
Execution Guardrails
MalwareDEADEYE

DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain.

T1480
Execution Guardrails
MalwareStealBit

StealBit will execute an empty infinite loop if it detects it is being run in the context of a debugger.

T1480
Execution Guardrails
MalwareQilin

Qilin can require a specific password to be passed by command-line argument during execution which must match a pre-defined value in the configuration in order for it to continue execution.

T1480
Execution Guardrails
MalwareLazyWiper

LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`.

T1480
Execution Guardrails
MalwareBitPaymer

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

T1480
Execution Guardrails
MalwareSmall Sieve

Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line.

T1480
Execution Guardrails
Toolevilginx2

evilginx2 can reject requests to phishing URLs if the User-Agent of the visitor doesn't match the allowlist REGEX filter for a specific lure.

T1480
Execution Guardrails
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has checked if it is running on a developer machine (rather than GitHub Actions) before executing a Python script for persistence. The script has also polled C2 every 50 minutes for additional payloads and aborted if the returned value contained YouTube.

T1480
Execution Guardrails
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel.

T1480
Execution Guardrails
MalwareCanisterWorm

CanisterWorm can base execution on specific conditions including halting its wiper component if Kubernetes is not found and if the target is not located in Iran.

T1480.001
Environmental Keying
MalwareNinja

Ninja can store its final payload in the Registry under `$HKLM\SOFTWARE\Classes\Interface\` encrypted with a dynamically generated key based on the drive’s serial number.

T1480.001
Environmental Keying
MalwarePikabot

Pikabot stops execution if the infected system language matches one of several languages, with various versions referencing: Georgian, Kazakh, Uzbek, Tajik, Russian, Ukrainian, Belarussian, and Slovenian.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1480.001
Environmental Keying
MalwarePUBLOAD

PUBLOAD has utilized environmental keying in the payload to include the victim volume serial number, computer name, username, and machine’s tick count.

T1480.001
Environmental Keying
MalwareInvisiMole

InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer.

T1480.001
Environmental Keying
MalwareROKRAT

ROKRAT relies on a specific victim hostname to execute and decrypt important strings.

T1480.001
Environmental Keying
MalwareWinnti for Windows

The Winnti for Windows dropper component can verify the existence of a single command line parameter and either terminate if it is not found or later use it as a decryption key.

T1480.001
Environmental Keying
MalwarePowerPunch

PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload.

T1480.002
Mutual Exclusion
MalwareTONESHELL

TONESHELL has created a mutex to avoid duplicate execution.

T1480.002
Mutual Exclusion
MalwareCLAIMLOADER

CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running.

T1480.002
Mutual Exclusion
MalwarePlugX

PlugX has leveraged a mutex in its infection process.

T1480.002
Mutual Exclusion
MalwarePureCrypter

PureCrypter code contains a global mutex.

T1480.002
Mutual Exclusion
MalwareLockBit 3.0

LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance.

T1480.002
Mutual Exclusion
MalwareGazer

Gazer creates a mutex using the hard-coded value `{531511FA-190D-5D85-8A4A-279F2F592CC7}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareEmbargo

Embargo has utilized a hardcoded mutex name of “LoadUpOnGunsBringYourFriends” using the `CreateMutexW()` function. Embargo has also utilized a hardcoded mutex name of “IntoTheFloodAgainSameOldTrip."

T1480.002
Mutual Exclusion
MalwareBPFDoor

When executed, BPFDoor attempts to create and lock a runtime file, `/var/run/initd.lock`, and exits if it fails using the specified file, resulting in a makeshift mutex.

T1480.002
Mutual Exclusion
MalwareBlack Basta

Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing.

T1480.002
Mutual Exclusion
MalwareStrelaStealer

StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection.

T1480.002
Mutual Exclusion
MalwareHiddenFace

HiddenFace can create a mutex to ensure only one instance is running at a time.

T1480.002
Mutual Exclusion
MalwareREvil

REvil attempts to create a mutex using a hard-coded value to ensure that no other instances of itself are running on the host.

T1480.002
Mutual Exclusion
MalwarePoisonIvy

PoisonIvy creates a mutex using either a custom or default value.

T1480.002
Mutual Exclusion
MalwareSUNSPOT

SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running.

T1480.002
Mutual Exclusion
MalwareGrimAgent

GrimAgent uses the last 64 bytes of the binary to compute a mutex name. If the generated name is invalid, it will default to the generic `mymutex`.

T1480.002
Mutual Exclusion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`.

T1480.002
Mutual Exclusion
MalwareTroll Stealer

Troll Stealer creates a mutex during installation to prevent duplicate execution.

T1480.002
Mutual Exclusion
MalwareQilin

Qilin can create a mutex to ensure only one instance is running.

T1482
Domain Trust Discovery
MalwareTrickBot

TrickBot can gather information about domain trusts by utilizing Nltest.

T1482
Domain Trust Discovery
MalwarePikabot

Pikabot will gather information concerning the Windows Domain the victim machine is a member of during execution.

T1482
Domain Trust Discovery
MalwareDUSTTRAP

DUSTTRAP can identify Active Directory information and related items.

T1482
Domain Trust Discovery
MalwareBADHATCH

BADHATCH can use `nltest.exe /domain_trusts` to discover domain trust relationships on a compromised machine.

T1482
Domain Trust Discovery
MalwareIcedID

IcedID used Nltest during initial discovery.

T1482
Domain Trust Discovery
MalwareSocGholish

SocGholish can profile compromised systems to identify domain trust relationships.

T1482
Domain Trust Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts.

T1482
Domain Trust Discovery
MalwareBazar

Bazar can use Nltest tools to obtain information about the domain.

T1482
Domain Trust Discovery
MalwareMgBot

MgBot includes modules for collecting information on local domain users and permissions.

T1482
Domain Trust Discovery
MalwareLAMEHUG

LAMEHUG can gather Active Directory domain information.

T1482
Domain Trust Discovery
MalwareQakBot

QakBot can run nltest /domain_trusts /all_trusts for domain trust discovery.

T1482
Domain Trust Discovery
ToolBloodHound

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.

T1482
Domain Trust Discovery
ToolPowerSploit

PowerSploit has modules such as Get-NetDomainTrust and Get-NetForestTrust to enumerate domain and forest trusts.

T1482
Domain Trust Discovery
ToolEmpire

Empire has modules for enumerating domain trusts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.