ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0024×

71 examples

TechniqueUsed byProcedure example
T1003.006
DCSync
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1005
Data from Local System
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1016.001
Internet Connection Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used GoldFinder to perform HTTP GET requests to check internet connectivity and identify HTTP proxy servers and other redirectors that an HTTP request travels through.

T1018
Remote System Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems.

T1021.001
Remote Desktop Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used RDP sessions from public-facing systems to internal servers.

T1021.002
SMB/Windows Admin Shares
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users.

T1021.006
Windows Remote Management
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts.

T1036.004
Masquerade Task or Service
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 named tasks `\Microsoft\Windows\SoftwareProtectionPlatform\EventCacheManager` in order to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1047
Windows Management Instrumentation
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exfiltrated collected data over a simple HTTPS request to a password-protected archive staged on a victim's OWA servers.

T1053.005
Scheduled Task
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1059.005
Visual Basic
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 wrote malware such as Sibot in Visual Basic.

T1069
Permission Groups Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell.

T1069.002
Domain Groups
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups.

T1070
Indicator Removal
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 temporarily replaced legitimate utilities with their own, executed their payload, and then restored the original file.

T1070.004
File Deletion
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 routinely removed their tools, including custom backdoors, once remote access was achieved.

T1070.006
Timestomp
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files.

T1070.008
Clear Mailbox Data
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`.

T1071.001
Web Protocols
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used HTTP for C2 and data exfiltration.

T1074.002
Remote Data Staging
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 staged data and files in password-protected archives on a victim's OWA server.

T1078
Valid Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used different compromised credentials for remote access and to move laterally.

T1078.002
Domain Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used domain administrators' accounts to help facilitate lateral movement on compromised networks.

T1078.003
Local Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks.

T1078.004
Cloud Accounts
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a compromised O365 administrator account to create a new Service Principal.

T1083
File and Directory Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`.

T1087
Account Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`.

T1087.002
Domain Account
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

T1090.001
Internal Proxy
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used SSH port forwarding capabilities on public-facing systems, and configured at least one instance of Cobalt Strike to use a network pipe over SMB.

T1098.001
Additional Cloud Credentials
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1098.003
Additional Cloud Roles
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle.

T1098.005
Device Registration
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command.

T1105
Ingress Tool Transfer
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded additional malware, such as TEARDROP and Cobalt Strike, onto a compromised host following initial access.

T1114.002
Remote Email Collection
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 collected emails from specific individuals, such as executives and IT staff, using `New-MailboxExportRequest` followed by `Get-MailboxExportRequest`.

T1133
External Remote Services
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used compromised identities to access networks via SSH, VPNs, and other remote access tools.

T1140
Deobfuscate/Decode Files or Information
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to decode their Raindrop malware.

T1190
Exploit Public-Facing Application
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel to regain access to a network.

T1195.002
Compromise Software Supply Chain
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software.

T1199
Trusted Relationship
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 gained access through compromised accounts at cloud solution partners, and used compromised certificates issued by Mimecast to authenticate to Mimecast customer systems.

T1213
Data from Information Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations.

T1213.003
Code Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 downloaded source code from code repositories.

T1218.011
Rundll32
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads.

T1482
Domain Trust Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains.

T1484.002
Trust Modification
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate.

T1539
Steal Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users.

T1546.003
Windows Management Instrumentation Event Subscription
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.