ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1482
Domain Trust Discovery
Tooldsquery

dsquery can be used to gather information on domain trusts with dsquery * -filter "(objectClass=trustedDomain)" -attr *.

T1482
Domain Trust Discovery
ToolPoshC2

PoshC2 has modules for enumerating domain trusts.

T1482
Domain Trust Discovery
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.

T1482
Domain Trust Discovery
ToolNltest

Nltest may be used to enumerate trusted domains by using commands such as nltest /domain_trusts.

T1482
Domain Trust Discovery
ToolRubeus

Rubeus can gather information about domain trusts.

T1482
Domain Trust Discovery
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

T1484.001
Group Policy Modification
MalwarePrestige

Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller.

T1484.001
Group Policy Modification
MalwareLockBit 3.0

LockBit 3.0 can enable options for propogation through Group Policy Objects.

T1484.001
Group Policy Modification
MalwareHermeticWiper

HermeticWiper has the ability to deploy through an infected system's default domain policy.

T1484.001
Group Policy Modification
MalwareLockBit 2.0

LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains.

T1484.001
Group Policy Modification
MalwareEgregor

Egregor can modify the GPO to evade detection.

T1484.001
Group Policy Modification
MalwareMeteor

Meteor can use group policy to push a scheduled task from the AD to all network machines.

T1484.001
Group Policy Modification
MalwareQilin

Qilin has pushed a scheduled task via a Group Policy Object for payload execution.

T1484.001
Group Policy Modification
ToolEmpire

Empire can use New-GPOImmediateTask to modify a GPO that will install and execute a malicious Scheduled Task/Job.

T1484.002
Trust Modification
ToolAADInternals

AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information.

T1485
Data Destruction
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1485
Data Destruction
MalwareAcidRain

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

T1485
Data Destruction
MalwareProxysvc

Proxysvc can overwrite files indicated by the attacker before deleting them.

T1485
Data Destruction
MalwareOlympic Destroyer

Olympic Destroyer overwrites files locally and on remote shares.

T1485
Data Destruction
MalwareDynoWiper

DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API.

T1485
Data Destruction
MalwareShrinkLocker

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1485
Data Destruction
MalwareApostle

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1485
Data Destruction
MalwareAcidPour

AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain.

T1485
Data Destruction
MalwareSameCoin

SameCoin can overwrite designated files on targeted systems with random bytes.

T1485
Data Destruction
MalwareDiavol

Diavol can delete specified files from a targeted system.

T1485
Data Destruction
MalwareKazuar

Kazuar can overwrite files with random data before deleting them.

T1485
Data Destruction
MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

T1485
Data Destruction
MalwareMultiLayer Wiper

MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally.

T1485
Data Destruction
MalwareXbash

Xbash has destroyed Linux-based databases as part of its ransomware capabilities.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1485
Data Destruction
MalwareStoneDrill

StoneDrill has a disk wiper module that targets files other than those in the Windows directory.

T1485
Data Destruction
MalwareHermeticWiper

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1485
Data Destruction
MalwareCaddyWiper

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

T1485
Data Destruction
MalwareMeteor

Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them.

T1485
Data Destruction
MalwareShai-Hulud

Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices.

T1485
Data Destruction
MalwareKillDisk

KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions.

T1485
Data Destruction
MalwareIndustroyer

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1485
Data Destruction
MalwareLazyWiper

LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable.

T1485
Data Destruction
MalwareDEADWOOD

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

T1485
Data Destruction
ToolRawDisk

RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.

T1485
Data Destruction
ToolSDelete

SDelete deletes data in a way that makes it unrecoverable.

T1485
Data Destruction
MalwareMini Shai-Hulud

Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary.

T1485
Data Destruction
MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

T1486
Data Encrypted for Impact
MalwareEKANS

EKANS uses standard encryption library functions to encrypt files.

T1486
Data Encrypted for Impact
MalwareSynAck

SynAck encrypts the victims machine followed by asking the victim to pay a ransom.

T1486
Data Encrypted for Impact
MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1486
Data Encrypted for Impact
MalwareRobbinHood

RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.

T1486
Data Encrypted for Impact
MalwareRansomHub

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.