Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupLotus Blossom | Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service. |
| T1016 System Network Configuration Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupLotus Blossom | Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| T1018 Remote System Discovery |
GroupLotus Blossom | Lotus Blossom has used Ping to identify remote systems. |
| T1046 Network Service Discovery |
GroupLotus Blossom | Lotus Blossom has used port scanners to enumerate services on remote hosts. |
| T1047 Windows Management Instrumentation |
GroupLotus Blossom | Lotus Blossom has used WMI to enable lateral movement. |
| T1049 System Network Connections Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1074.001 Local Data Staging |
GroupLotus Blossom | Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1083 File and Directory Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines. |
| T1087.001 Local Account |
GroupLotus Blossom | Lotus Blossom has used commands such as `net` to profile local system users. |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1090.001 Internal Proxy |
GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.003 Multi-hop Proxy |
GroupLotus Blossom | Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1112 Modify Registry |
GroupLotus Blossom | Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1134 Access Token Manipulation |
GroupLotus Blossom | Lotus Blossom has retrieved process tokens for processes to adjust the privileges of the launch process or other items. |
| T1482 Domain Trust Discovery |
GroupLotus Blossom | Lotus Blossom has used tools such as AdFind to make Active Directory queries. |
| T1539 Steal Web Session Cookie |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome. |
| T1543.003 Windows Service |
GroupLotus Blossom | Lotus Blossom has configured tools such as Sagerunex to run as Windows services. |
| T1560.001 Archive via Utility |
GroupLotus Blossom | Lotus Blossom has used WinRAR for compressing data in RAR format. |
| T1560.003 Archive via Custom Method |
GroupLotus Blossom | Lotus Blossom has used custom tools to compress and archive data on victim systems. |
| T1588.002 Tool |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.