ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0061×

22 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

T1003.002
Security Account Manager
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `reg save` to retrieve credentials from the Security Account Manager (SAM) database.

T1018
Remote System Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used Ping for reconnaissance.

T1021.001
Remote Desktop Protocol
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

T1033
System Owner/User Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information.

T1036.005
Match Legitimate Resource Name or Location
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors attempted to make filenames appear legitimate by tailoring them to the victim organization.

T1059.003
Windows Command Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `cmd.exe` as a default method of execution for a custom version of Mimikatz named bK2o.exe.

T1069.001
Local Groups
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

T1070.004
File Deletion
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deleted files delivered to compromised hosts, often named with the pattern do.* such as do.exe.

T1087.001
Local Account
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

T1098.004
SSH Authorized Keys
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution.

T1106
Native API
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used native API such as `GetUserInfo`.

T1190
Exploit Public-Facing Application
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SQL injection to compromise publicly exposed web and database servers.

T1219.001
IDE Tunneling
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created Visual Studio Code dev tunnels to access targeted endpoints through the browser-based version of Visual Studio Code.

T1505.003
Web Shell
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors deployed a PHP-based webshell to maintain persistent access.

T1543.003
Windows Service
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code.

T1550.002
Pass the Hash
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally.

T1569.002
Service Execution
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service.

T1588.002
Tool
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used third party tools including custom implementations of Mimikatz.

T1591
Gather Victim Org Information
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors concealed malicious activity by using terms that aligned with the technological context of the targeted organization.

T1614.001
System Language Discovery
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local language of targeted organizations to disguise file system activity.

T1665
Hide Infrastructure
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used public Cloud infrastructure to mask malicious activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.