Real-world descriptions of how a group, tool or campaign used a technique.
46 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1003.003 NTDS |
GroupmenuPass | menuPass has used Ntdsutil to dump credentials. |
| T1003.004 LSA Secrets |
GroupmenuPass | menuPass has used a modified version of pentesting tools wmiexec.vbs and secretsdump.py to dump credentials. |
| T1005 Data from Local System |
GroupmenuPass | menuPass has collected various files from the compromised computers. |
| T1016 System Network Configuration Discovery |
GroupmenuPass | menuPass has used several tools to scan for open NetBIOS nameservers and enumerate NetBIOS sessions. |
| T1018 Remote System Discovery |
GroupmenuPass | menuPass uses scripts to enumerate IP ranges on the victim network. menuPass has also issued the command |
| T1021.001 Remote Desktop Protocol |
GroupmenuPass | menuPass has used RDP connections to move across the victim network. |
| T1021.004 SSH |
GroupmenuPass | menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1027.013 Encrypted/Encoded File |
GroupmenuPass | menuPass has encoded strings in its malware with base64 as well as with a simple, single-byte XOR obfuscation using key 0x40. |
| T1036 Masquerading |
GroupmenuPass | menuPass has used esentutl to change file extensions to their true type that were masquerading as .txt files. |
| T1036.003 Rename Legitimate Utilities |
GroupmenuPass | menuPass has renamed certutil and moved it to a different location on the system to avoid detection based on use of the tool. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupmenuPass | menuPass has been seen changing malicious files to appear legitimate. |
| T1039 Data from Network Shared Drive |
GroupmenuPass | menuPass has collected data from remote systems by mounting network shares with |
| T1046 Network Service Discovery |
GroupmenuPass | menuPass has used tcping.exe, similar to Ping, to probe port status on systems of interest. |
| T1047 Windows Management Instrumentation |
GroupmenuPass | menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI. |
| T1049 System Network Connections Discovery |
GroupmenuPass | menuPass has used |
| T1053.005 Scheduled Task |
GroupmenuPass | menuPass has used a script (atexec.py) to execute a command on a target machine via Task Scheduler. |
| T1055.012 Process Hollowing |
GroupmenuPass | menuPass has used process hollowing in iexplore.exe to load the RedLeaves implant. |
| T1056.001 Keylogging |
GroupmenuPass | menuPass has used key loggers to steal usernames and passwords. |
| T1059.001 PowerShell |
GroupmenuPass | menuPass uses PowerSploit to inject shellcode into PowerShell. |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1070.003 Clear Command History |
GroupmenuPass | menuPass has used Wevtutil to remove PowerShell execution logs. |
| T1070.004 File Deletion |
GroupmenuPass | A menuPass macro deletes files after it has decoded and decompressed them. |
| T1074.001 Local Data Staging |
GroupmenuPass | menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin. |
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1083 File and Directory Discovery |
GroupmenuPass | menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos. |
| T1087.002 Domain Account |
GroupmenuPass | menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
| T1105 Ingress Tool Transfer |
GroupmenuPass | menuPass has installed updates and new malware on victims. |
| T1106 Native API |
GroupmenuPass | menuPass has used native APIs including |
| T1119 Automated Collection |
GroupmenuPass | menuPass has used the Csvde tool to collect Active Directory files and data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupmenuPass | menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used |
| T1190 Exploit Public-Facing Application |
GroupmenuPass | menuPass has leveraged vulnerabilities in Pulse Secure VPNs to hijack sessions. |
| T1199 Trusted Relationship |
GroupmenuPass | menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest. |
| T1204.002 Malicious File |
GroupmenuPass | menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns. |
| T1210 Exploitation of Remote Services |
GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| T1218.004 InstallUtil |
GroupmenuPass | menuPass has used |
| T1553.002 Code Signing |
GroupmenuPass | menuPass has resized and added data to the certificate table to enable the signing of modified files with legitimate signatures. |
| T1560 Archive Collected Data |
GroupmenuPass | menuPass has encrypted files and information before exfiltration. |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1566.001 Spearphishing Attachment |
GroupmenuPass | menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents. |
| T1568.001 Fast Flux DNS |
GroupmenuPass | menuPass has used dynamic DNS service providers to host malicious domains. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
| T1583.001 Domains |
GroupmenuPass | menuPass has registered malicious domains for use in intrusion campaigns. |
| T1588.002 Tool |
GroupmenuPass | menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.