Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT1 | APT1 has been known to use credential dumping using Mimikatz. |
| T1005 Data from Local System |
GroupAPT1 | APT1 has collected files from a local victim. |
| T1007 System Service Discovery |
GroupAPT1 | APT1 used the commands |
| T1016 System Network Configuration Discovery |
GroupAPT1 | APT1 used the |
| T1021.001 Remote Desktop Protocol |
GroupAPT1 | The APT1 group is known to have used RDP during operations. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1049 System Network Connections Discovery |
GroupAPT1 | APT1 used the |
| T1057 Process Discovery |
GroupAPT1 | APT1 gathered a list of running processes on the system using |
| T1059.003 Windows Command Shell |
GroupAPT1 | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. |
| T1087.001 Local Account |
GroupAPT1 | APT1 used the commands |
| T1114.001 Local Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| T1114.002 Remote Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1119 Automated Collection |
GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1135 Network Share Discovery |
GroupAPT1 | APT1 listed connected network shares. |
| T1550.002 Pass the Hash |
GroupAPT1 | The APT1 group is known to have used pass the hash. |
| T1560.001 Archive via Utility |
GroupAPT1 | APT1 has used RAR to compress files before moving them outside of the victim network. |
| T1566.001 Spearphishing Attachment |
GroupAPT1 | APT1 has sent spearphishing emails containing malicious attachments. |
| T1566.002 Spearphishing Link |
GroupAPT1 | APT1 has sent spearphishing emails containing hyperlinks to malicious files. |
| T1583.001 Domains |
GroupAPT1 | APT1 has registered hundreds of domains for use in operations. |
| T1584.001 Domains |
GroupAPT1 | APT1 hijacked FQDNs associated with legitimate websites hosted by hop points. |
| T1585.002 Email Accounts |
GroupAPT1 | APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. |
| T1588.001 Malware |
GroupAPT1 | APT1 used publicly available malware for privilege escalation. |
| T1588.002 Tool |
GroupAPT1 | APT1 has used various open-source tools for privilege escalation purposes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.