ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0077×

17 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz.

T1003.004
LSA Secrets
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.005
Cached Domain Credentials
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1018
Remote System Discovery
GroupLeafminer

Leafminer used Microsoft’s Sysinternals tools to gather detailed information about remote systems.

T1027.010
Command Obfuscation
GroupLeafminer

Leafminer obfuscated scripts that were used on victim machines.

T1046
Network Service Discovery
GroupLeafminer

Leafminer scanned network services to search for vulnerabilities in the victim system.

T1055.013
Process Doppelgänging
GroupLeafminer

Leafminer has used Process Doppelgänging to evade security software while deploying tools on compromised systems.

T1059.007
JavaScript
GroupLeafminer

Leafminer infected victims using JavaScript code.

T1083
File and Directory Discovery
GroupLeafminer

Leafminer used a tool called MailSniper to search for files on the desktop and another utility called Sobolsoft to extract attachments from EML files.

T1110.003
Password Spraying
GroupLeafminer

Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying.

T1114.002
Remote Email Collection
GroupLeafminer

Leafminer used a tool called MailSniper to search through the Exchange server mailboxes for keywords.

T1136.001
Local Account
GroupLeafminer

Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine.

T1189
Drive-by Compromise
GroupLeafminer

Leafminer has infected victims using watering holes.

T1552.001
Credentials In Files
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555
Credentials from Password Stores
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555.003
Credentials from Web Browsers
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1588.002
Tool
GroupLeafminer

Leafminer has obtained and used tools such as LaZagne, Mimikatz, PsExec, and MailSniper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.