ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0024×

71 examples

TechniqueUsed byProcedure example
T1550
Use Alternate Authentication Material
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services.

T1550.001
Application Access Token
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment.

T1550.004
Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

T1552.004
Private Keys
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates.

T1553.002
Code Signing
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.

T1555
Credentials from Password Stores
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords.

T1555.003
Credentials from Web Browsers
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.

T1558.003
Kerberoasting
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline.

T1560.001
Archive via Utility
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives.

T1568
Dynamic Resolution
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used dynamic DNS resolution to construct and resolve to randomly-generated subdomains for C2.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

T1584.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 compromised domains to use for C2.

T1587.001
Malware
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP.

T1589.001
Credentials
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 conducted credential theft operations to obtain credentials to be used for access to victim environments.

T1606.001
Web Cookies
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 bypassed MFA set on OWA accounts by generating a cookie value from a previously stolen secret key.

T1606.002
SAML Tokens
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates.

T1665
Hide Infrastructure
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 set the hostnames of their C2 infrastructure to match legitimate hostnames in the victim environment. They also used IP addresses originating from the same country as the victim for their VPN infrastructure.

T1680
Local Storage Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk.

T1685
Disable or Modify Tools
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products.

T1685.001
Disable or Modify Windows Event Log
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs.

T1686
Disable or Modify System Firewall
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.