Real-world descriptions of how a group, tool or campaign used a technique.
71 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1550 Use Alternate Authentication Material |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services. |
| T1550.001 Application Access Token |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment. |
| T1550.004 Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account. |
| T1552.004 Private Keys |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates. |
| T1553.002 Code Signing |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle. |
| T1555 Credentials from Password Stores |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords. |
| T1555.003 Credentials from Web Browsers |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome. |
| T1558.003 Kerberoasting |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1568 Dynamic Resolution |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2. |
| T1583.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers. |
| T1584.001 Domains |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 compromised domains to use for C2. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1589.001 Credentials |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments. |
| T1606.001 Web Cookies |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key. |
| T1606.002 SAML Tokens |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates. |
| T1665 Hide Infrastructure |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure. |
| T1680 Local Storage Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk. |
| T1685 Disable or Modify Tools |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs. |
| T1686 Disable or Modify System Firewall |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.