Real-world descriptions of how a group, tool or campaign used a technique.
70 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1190 Exploit Public-Facing Application |
CampaignOperation Wocao | During Operation Wocao, threat actors gained initial access by exploiting vulnerabilities in JBoss webservers. |
| T1505.003 Web Shell |
CampaignOperation Wocao | During Operation Wocao, threat actors used their own web shells, as well as those previously placed on target systems by other threat actors, for reconnaissance and lateral movement. |
| T1518 Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of installed software on the infected system. |
| T1518.001 Security Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used scripts to detect security software. |
| T1552.004 Private Keys |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store. |
| T1555.005 Password Managers |
CampaignOperation Wocao | During Operation Wocao, threat actors accessed and collected credentials from password managers. |
| T1558.003 Kerberoasting |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline. |
| T1560.001 Archive via Utility |
CampaignOperation Wocao | During Operation Wocao, threat actors archived collected files with WinRAR, prior to exfiltration. |
| T1569.002 Service Execution |
CampaignOperation Wocao | During Operation Wocao, threat actors created services on remote systems for execution purposes. |
| T1570 Lateral Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors used SMB to copy files to and from target systems. |
| T1571 Non-Standard Port |
CampaignOperation Wocao | During Operation Wocao, the threat actors used uncommon high ports for its backdoor C2, including ports 25667 and 47000. |
| T1573.002 Asymmetric Cryptography |
CampaignOperation Wocao | During Operation Wocao, threat actors' proxy implementation "Agent" upgraded the socket in use to a TLS socket. |
| T1583.004 Server |
CampaignOperation Wocao | For Operation Wocao, the threat actors purchased servers with Bitcoin to use during the operation. |
| T1585.002 Email Accounts |
CampaignOperation Wocao | For Operation Wocao, the threat actors registered email accounts to use during the campaign. |
| T1587.001 Malware |
CampaignOperation Wocao | During Operation Wocao, threat actors developed their own custom webshells to upload to compromised servers. |
| T1588.002 Tool |
CampaignOperation Wocao | For Operation Wocao, the threat actors obtained a variety of open source tools, including JexBoss, KeeThief, and BloodHound. |
| T1589 Gather Victim Identity Information |
CampaignOperation Wocao | During Operation Wocao, threat actors targeted people based on their organizational roles and privileges. |
| T1680 Local Storage Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered the local disks attached to the system and their hardware information including manufacturer and model. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation Wocao | During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`. |
| T1686.003 Windows Host Firewall |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.