ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0038×

25 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

T1021.001
Remote Desktop Protocol
CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

T1021.002
SMB/Windows Admin Shares
CampaignHomeLand Justice

During HomeLand Justice, threat actors used SMB for lateral movement.

T1036.005
Match Legitimate Resource Name or Location
CampaignHomeLand Justice

During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.

T1041
Exfiltration Over C2 Channel
CampaignHomeLand Justice

During HomeLand Justice, threat actors used HTTP to transfer data from compromised Exchange servers.

T1046
Network Service Discovery
CampaignHomeLand Justice

During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems.

T1047
Windows Management Instrumentation
CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1059.001
PowerShell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery.

T1059.003
Windows Command Shell
CampaignHomeLand Justice

During HomeLand Justice, threat actors used Windows batch files for persistence and execution.

T1078
Valid Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a compromised Exchange account to search mailboxes and create new Exchange accounts.

T1078.001
Default Accounts
CampaignHomeLand Justice

During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket.

T1087.003
Email Account
CampaignHomeLand Justice

During HomeLand Justice, threat actors used compromised Exchange accounts to search mailboxes for administrator accounts.

T1098.002
Additional Email Delegate Permissions
CampaignHomeLand Justice

During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes.

T1105
Ingress Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure.

T1114.002
Remote Email Collection
CampaignHomeLand Justice

During HomeLand Justice, threat actors made multiple HTTP POST requests to the Exchange servers of the victim organization to transfer data.

T1134.001
Token Impersonation/Theft
CampaignHomeLand Justice

During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`.

T1190
Exploit Public-Facing Application
CampaignHomeLand Justice

For HomeLand Justice, threat actors exploited CVE-2019-0604 in Microsoft SharePoint for initial access.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1505.003
Web Shell
CampaignHomeLand Justice

For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence.

T1561.002
Disk Structure Wipe
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.

T1570
Lateral Tool Transfer
CampaignHomeLand Justice

During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines.

T1588.002
Tool
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket.

T1588.003
Code Signing Certificates
CampaignHomeLand Justice

During HomeLand Justice, threat actors used tools with legitimate code signing certificates.

T1685
Disable or Modify Tools
CampaignHomeLand Justice

During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus.

T1685.001
Disable or Modify Windows Event Log
CampaignHomeLand Justice

During HomeLand Justice, threat actors deleted Windows events and application logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.