Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1027.013 Encrypted/Encoded File |
GroupAPT33 | APT33 has used base64 to encode payloads. |
| T1040 Network Sniffing |
GroupAPT33 | APT33 has used SniffPass to collect credentials by sniffing network traffic. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT33 | APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1053.005 Scheduled Task |
GroupAPT33 | APT33 has created a scheduled task to execute a .vbe file multiple times a day. |
| T1059.001 PowerShell |
GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1059.005 Visual Basic |
GroupAPT33 | APT33 has used VBScript to initiate the delivery of payloads. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT33 | APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1071.001 Web Protocols |
GroupAPT33 | APT33 has used HTTP for command and control. |
| T1078 Valid Accounts |
GroupAPT33 | APT33 has used valid accounts for initial access and privilege escalation. |
| T1078.004 Cloud Accounts |
GroupAPT33 | APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1105 Ingress Tool Transfer |
GroupAPT33 | APT33 has downloaded additional files and programs from its C2 server. |
| T1110.003 Password Spraying |
GroupAPT33 | APT33 has used password spraying to gain access to target systems. |
| T1132.001 Standard Encoding |
GroupAPT33 | APT33 has used base64 to encode command and control traffic. |
| T1203 Exploitation for Client Execution |
GroupAPT33 | APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774). |
| T1204.001 Malicious Link |
GroupAPT33 | APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails. |
| T1204.002 Malicious File |
GroupAPT33 | APT33 has used malicious e-mail attachments to lure victims into executing malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT33 | APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT33 | APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.006 Group Policy Preferences |
GroupAPT33 | APT33 has used a variety of publicly available tools like Gpppassword to gather credentials. |
| T1555 Credentials from Password Stores |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1560.001 Archive via Utility |
GroupAPT33 | APT33 has used WinRAR to compress data prior to exfil. |
| T1566.001 Spearphishing Attachment |
GroupAPT33 | APT33 has sent spearphishing e-mails with archive attachments. |
| T1566.002 Spearphishing Link |
GroupAPT33 | APT33 has sent spearphishing emails containing links to .hta files. |
| T1571 Non-Standard Port |
GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
| T1573.001 Symmetric Cryptography |
GroupAPT33 | APT33 has used AES for encryption of command and control traffic. |
| T1588.002 Tool |
GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.