ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0014×

70 examples

TechniqueUsed byProcedure example
T1190
Exploit Public-Facing Application
CampaignOperation Wocao

During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers.

T1505.003
Web Shell
CampaignOperation Wocao

During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement.

T1518
Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of installed software on the infected system.

T1518.001
Security Software Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors used scripts to detect security software.

T1552.004
Private Keys
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store.

T1555.005
Password Managers
CampaignOperation Wocao

During Operation Wocao, threat actors accessed and collected credentials from password managers.

T1558.003
Kerberoasting
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline.

T1560.001
Archive via Utility
CampaignOperation Wocao

During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration.

T1569.002
Service Execution
CampaignOperation Wocao

During Operation Wocao, threat actors created services on remote systems for execution purposes.

T1570
Lateral Tool Transfer
CampaignOperation Wocao

During Operation Wocao, threat actors used SMB to copy files to and from target systems.

T1571
Non-Standard Port
CampaignOperation Wocao

During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000.

T1573.002
Asymmetric Cryptography
CampaignOperation Wocao

During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket.

T1583.004
Server
CampaignOperation Wocao

For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation.

T1585.002
Email Accounts
CampaignOperation Wocao

For Operation Wocao, the threat actors registered email accounts to use during the campaign.

T1587.001
Malware
CampaignOperation Wocao

During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers.

T1588.002
Tool
CampaignOperation Wocao

For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound.

T1589
Gather Victim Identity Information
CampaignOperation Wocao

During Operation Wocao, threat actors targeted people based on their organizational roles and privileges.

T1680
Local Storage Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model.

T1685.005
Clear Windows Event Logs
CampaignOperation Wocao

During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`.

T1686.003
Windows Host Firewall
CampaignOperation Wocao

During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.