Real-world descriptions of how a group, tool or campaign used a technique.
44 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT3 | APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
| T1005 Data from Local System |
GroupAPT3 | APT3 will identify Microsoft Office documents on the victim's computer. |
| T1016 System Network Configuration Discovery |
GroupAPT3 | A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1018 Remote System Discovery |
GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| T1021.001 Remote Desktop Protocol |
GroupAPT3 | APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT3 | APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| T1027 Obfuscated Files or Information |
GroupAPT3 | APT3 obfuscates files or information to help evade defensive measures. |
| T1027.002 Software Packing |
GroupAPT3 | APT3 has been known to pack their tools. |
| T1027.005 Indicator Removal from Tools |
GroupAPT3 | APT3 has been known to remove indicators of compromise from tools. |
| T1033 System Owner/User Discovery |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1036.010 Masquerade Account Name |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1041 Exfiltration Over C2 Channel |
GroupAPT3 | APT3 has a tool that exfiltrates data over the C2 channel. |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1053.005 Scheduled Task |
GroupAPT3 | An APT3 downloader creates persistence by creating the following scheduled task: |
| T1056.001 Keylogging |
GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| T1057 Process Discovery |
GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| T1059.001 PowerShell |
GroupAPT3 | APT3 has used PowerShell on victim systems to download and run payloads after exploitation. |
| T1059.003 Windows Command Shell |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1069 Permission Groups Discovery |
GroupAPT3 | APT3 has a tool that can enumerate the permissions associated with Windows groups. |
| T1070.004 File Deletion |
GroupAPT3 | APT3 has a tool that can delete files. |
| T1074.001 Local Data Staging |
GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| T1078.002 Domain Accounts |
GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| T1082 System Information Discovery |
GroupAPT3 | APT3 has a tool that can obtain information about the local system. |
| T1083 File and Directory Discovery |
GroupAPT3 | APT3 has a tool that looks for files and directories on the local file system. |
| T1087.001 Local Account |
GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| T1090.002 External Proxy |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1095 Non-Application Layer Protocol |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT3 | APT3 has been known to add created accounts to local admin groups to maintain elevated access. |
| T1104 Multi-Stage Channels |
GroupAPT3 | An APT3 downloader first establishes a SOCKS5 connection to 192.157.198[.]103 using TCP port 1913; once the server response is verified, it then requests a connection to 192.184.60[.]229 on TCP port 81. |
| T1105 Ingress Tool Transfer |
GroupAPT3 | APT3 has a tool that can copy files to remote machines. |
| T1110.002 Password Cracking |
GroupAPT3 | APT3 has been known to brute force password hashes to be able to leverage plain text credentials. |
| T1136.001 Local Account |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1203 Exploitation for Client Execution |
GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| T1204.001 Malicious Link |
GroupAPT3 | APT3 has lured victims into clicking malicious links delivered through spearphishing. |
| T1218.011 Rundll32 |
GroupAPT3 | APT3 has a tool that can run DLLs. |
| T1543.003 Windows Service |
GroupAPT3 | APT3 has a tool that creates a new service for persistence. |
| T1546.008 Accessibility Features |
GroupAPT3 | APT3 replaces the Sticky Keys binary |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT3 | APT3 places scripts in the startup folder for persistence. |
| T1552.001 Credentials In Files |
GroupAPT3 | APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| T1560.001 Archive via Utility |
GroupAPT3 | APT3 has used tools to compress data before exfilling it. |
| T1564.003 Hidden Window |
GroupAPT3 | APT3 has been known to use |
| T1566.002 Spearphishing Link |
GroupAPT3 | APT3 has sent spearphishing emails containing malicious links. |
| T1574.001 DLL |
GroupAPT3 | APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.