Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz. |
| T1003.004 LSA Secrets |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1018 Remote System Discovery |
GroupLeafminer | Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems. |
| T1027.010 Command Obfuscation |
GroupLeafminer | Leafminer obfuscated scripts that were used on victim machines. |
| T1046 Network Service Discovery |
GroupLeafminer | Leafminer scanned network services to search for vulnerabilities in the victim system. |
| T1055.013 Process Doppelgänging |
GroupLeafminer | Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems. |
| T1059.007 JavaScript |
GroupLeafminer | Leafminer infected victims using JavaScript code. |
| T1083 File and Directory Discovery |
GroupLeafminer | Leafminer used a tool called MailSniper to search for files on the desktop and another utility called Sobolsoft to extract attachments from EML files. |
| T1110.003 Password Spraying |
GroupLeafminer | Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying. |
| T1114.002 Remote Email Collection |
GroupLeafminer | Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords. |
| T1136.001 Local Account |
GroupLeafminer | Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine. |
| T1189 Drive-by Compromise |
GroupLeafminer | Leafminer has infected victims using watering holes. |
| T1552.001 Credentials In Files |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555 Credentials from Password Stores |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555.003 Credentials from Web Browsers |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1588.002 Tool |
GroupLeafminer | Leafminer has obtained and used tools such as LaZagne, Mimikatz, PsExec, and MailSniper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.