Real-world descriptions of how a group, tool or campaign used a technique.
71 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.006 DCSync |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1005 Data from Local System |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1016.001 Internet Connection Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through. |
| T1018 Remote System Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1021.001 Remote Desktop Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers. |
| T1021.002 SMB/Windows Admin Shares |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
| T1021.006 Windows Remote Management |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts. |
| T1036.004 Masquerade Task or Service |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1047 Windows Management Instrumentation |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers. |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1059.005 Visual Basic |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic. |
| T1069 Permission Groups Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell. |
| T1069.002 Domain Groups |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups. |
| T1070 Indicator Removal |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file. |
| T1070.004 File Deletion |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved. |
| T1070.006 Timestomp |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files. |
| T1070.008 Clear Mailbox Data |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`. |
| T1071.001 Web Protocols |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration. |
| T1074.002 Remote Data Staging |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server. |
| T1078 Valid Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally. |
| T1078.002 Domain Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks. |
| T1078.003 Local Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks. |
| T1078.004 Cloud Accounts |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal. |
| T1083 File and Directory Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`. |
| T1087 Account Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`. |
| T1087.002 Domain Account |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
| T1090.001 Internal Proxy |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB. |
| T1098.001 Additional Cloud Credentials |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals. |
| T1098.002 Additional Email Delegate Permissions |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals. |
| T1098.003 Additional Cloud Roles |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle. |
| T1098.005 Device Registration |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command. |
| T1105 Ingress Tool Transfer |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access. |
| T1114.002 Remote Email Collection |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`. |
| T1133 External Remote Services |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware. |
| T1190 Exploit Public-Facing Application |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1199 Trusted Relationship |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems. |
| T1213 Data from Information Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations. |
| T1213.003 Code Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 downloaded source code from code repositories. |
| T1218.011 Rundll32 |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1484.002 Trust Modification |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate. |
| T1539 Steal Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users. |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.