ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
MalwareSUPERNOVA

SUPERNOVA is a Web shell.

T1505.003
Web Shell
MalwareNeo-reGeorg

Neo-reGeorg can be installed on compromised web servers to tunnel C2 connections.

T1505.003
Web Shell
MalwareFRAMESTING

FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareWIREFIRE

WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
MalwareSTEADYPULSE

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.

T1505.003
Web Shell
MalwarePHASEJAM

PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance.

T1505.003
Web Shell
MalwareSLIGHTPULSE

SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers.

T1505.003
Web Shell
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

T1505.004
IIS Components
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.

T1505.004
IIS Components
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors modified Internet Information Services (IIS) components to load suspicious .NET assemblies for persistence.

T1505.004
IIS Components
MalwareOwaAuth

OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL.

T1505.004
IIS Components
MalwareRGDoor

RGDoor establishes persistence on webservers as an IIS module.

T1505.004
IIS Components
MalwareIceApple

IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities.

T1505.006
vSphere Installation Bundles
GroupUNC3886

UNC3886 has used vSphere Installation Bundles (VIBs) to install malware and establish persistence across ESXi hypervisors.

T1505.006
vSphere Installation Bundles
MalwareVIRTUALPIE

VIRTUALPIE has been installed on VMware ESXi servers through malicious vSphere Installation Bundles (VIBs).

T1518
Software Discovery
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery.

T1518
Software Discovery
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed.

T1518
Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of installed software on the infected system.

T1518
Software Discovery
GroupSideCopy

SideCopy has collected browser information from a compromised host.

T1518
Software Discovery
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems for information on installed software.

T1518
Software Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.

T1518
Software Discovery
GroupSidewinder

Sidewinder has used tools to enumerate software installed on an infected host.

T1518
Software Discovery
GroupMustang Panda

Mustang Panda has searched the victim system for the InstallUtil.exe program and its version.

T1518
Software Discovery
GroupWindigo

Windigo has used a script to detect installed software on targeted systems.

T1518
Software Discovery
GroupTropic Trooper

Tropic Trooper's backdoor could list the infected system's installed software.

T1518
Software Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used tools to enumerate software installed on an infected host.

T1518
Software Discovery
GroupWindshift

Windshift has used malware to identify installed software.

T1518
Software Discovery
GroupInception

Inception has enumerated installed software on compromised systems.

T1518
Software Discovery
GroupHEXANE

HEXANE has enumerated programs installed on an infected machine.

T1518
Software Discovery
MalwareOrz

Orz can gather the victim's Internet Explorer version.

T1518
Software Discovery
MalwareIronWind

IronWind can list installed software on targeted hosts.

T1518
Software Discovery
MalwareInvisibleFerret

InvisibleFerret has gathered installed programs and running processes.

T1518
Software Discovery
MalwarePUBLOAD

PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys.

T1518
Software Discovery
MalwareWoody RAT

Woody RAT can collect .NET, PowerShell, and Python information from an infected host.

T1518
Software Discovery
MalwareCuckoo Stealer

Cuckoo Stealer has the ability to search systems for installed applications.

T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1518
Software Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can list PHP server configuration details.

T1518
Software Discovery
MalwareSiloscape

Siloscape searches for the kubectl binary.

T1518
Software Discovery
MalwareMarkiRAT

MarkiRAT can check for the Telegram installation directory by enumerating the files on disk.

T1518
Software Discovery
MalwareSocGholish

SocGholish can identify the victim's browser in order to serve the correct fake update page.

T1518
Software Discovery
MalwareSpicyOmelette

SpicyOmelette can enumerate running software on a targeted system.

T1518
Software Discovery
MalwareLightSpy

If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration.

T1518
Software Discovery
MalwareDyre

Dyre has the ability to identify installed programs on a compromised host.

T1518
Software Discovery
MalwareDustySky

DustySky lists all installed software for the infected machine.

T1518
Software Discovery
MalwareSVCReady

SVCReady can collect a list of installed software from an infected host.

T1518
Software Discovery
MalwareCharmPower

CharmPower can list the installed applications on a compromised host.

T1518
Software Discovery
MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

T1518
Software Discovery
MalwareGlassWorm

GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1518
Software Discovery
MalwareKGH_SPY

KGH_SPY can collect information on installed applications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.