Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials. |
| T1003.002 Security Account Manager |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database. |
| T1018 Remote System Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used Ping for reconnaissance. |
| T1021.001 Remote Desktop Protocol |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors moved laterally using RDP. |
| T1033 System Owner/User Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization. |
| T1059.003 Windows Command Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe. |
| T1069.001 Local Groups |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| T1070.004 File Deletion |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe. |
| T1087.001 Local Account |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
| T1098.004 SSH Authorized Keys |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution. |
| T1106 Native API |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used native API such as `GetUserInfo`. |
| T1190 Exploit Public-Facing Application |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers. |
| T1219.001 IDE Tunneling |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code. |
| T1505.003 Web Shell |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access. |
| T1543.003 Windows Service |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code. |
| T1550.002 Pass the Hash |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally. |
| T1569.002 Service Execution |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service. |
| T1588.002 Tool |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz. |
| T1591 Gather Victim Org Information |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization. |
| T1614.001 System Language Discovery |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity. |
| T1665 Hide Infrastructure |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.