Real-world descriptions of how a group, tool or campaign used a technique.
31 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupGALLIUM | GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines. |
| T1003.002 Security Account Manager |
GroupGALLIUM | GALLIUM used |
| T1005 Data from Local System |
GroupGALLIUM | GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry. |
| T1016 System Network Configuration Discovery |
GroupGALLIUM | GALLIUM used |
| T1018 Remote System Discovery |
GroupGALLIUM | GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as |
| T1027 Obfuscated Files or Information |
GroupGALLIUM | GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection. |
| T1027.002 Software Packing |
GroupGALLIUM | GALLIUM packed some payloads using different types of packers, both known and custom. |
| T1027.005 Indicator Removal from Tools |
GroupGALLIUM | GALLIUM ensured each payload had a unique hash, including by using different types of packers. |
| T1033 System Owner/User Discovery |
GroupGALLIUM | GALLIUM used |
| T1036.003 Rename Legitimate Utilities |
GroupGALLIUM | GALLIUM used a renamed cmd.exe file to evade detection. |
| T1041 Exfiltration Over C2 Channel |
GroupGALLIUM | GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data. |
| T1047 Windows Management Instrumentation |
GroupGALLIUM | GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets. |
| T1049 System Network Connections Discovery |
GroupGALLIUM | GALLIUM used |
| T1053.005 Scheduled Task |
GroupGALLIUM | GALLIUM established persistence for PoisonIvy by created a scheduled task. |
| T1059.001 PowerShell |
GroupGALLIUM | GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines. |
| T1059.003 Windows Command Shell |
GroupGALLIUM | GALLIUM used the Windows command shell to execute commands. |
| T1074.001 Local Data Staging |
GroupGALLIUM | GALLIUM compressed and staged files in multi-part archives in the Recycle Bin prior to exfiltration. |
| T1078 Valid Accounts |
GroupGALLIUM | GALLIUM leveraged valid accounts to maintain access to a victim network. |
| T1090.002 External Proxy |
GroupGALLIUM | GALLIUM used a modified version of HTRAN to redirect connections between networks. |
| T1105 Ingress Tool Transfer |
GroupGALLIUM | GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN. |
| T1133 External Remote Services |
GroupGALLIUM | GALLIUM has used VPN services, including SoftEther VPN, to access and maintain persistence in victim environments. |
| T1136.002 Domain Account |
GroupGALLIUM | GALLIUM created high-privileged domain user accounts to maintain access to victim networks. |
| T1190 Exploit Public-Facing Application |
GroupGALLIUM | GALLIUM exploited a publicly-facing servers including Wildfly/JBoss servers to gain access to the network. |
| T1505.003 Web Shell |
GroupGALLIUM | GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration. |
| T1550.002 Pass the Hash |
GroupGALLIUM | GALLIUM used dumped hashes to authenticate to other machines via pass the hash. |
| T1553.002 Code Signing |
GroupGALLIUM | GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC. |
| T1560.001 Archive via Utility |
GroupGALLIUM | GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration. |
| T1570 Lateral Tool Transfer |
GroupGALLIUM | GALLIUM has used PsExec to move laterally between hosts in the target network. |
| T1574.001 DLL |
GroupGALLIUM | GALLIUM used DLL side-loading to covertly load PoisonIvy into memory on the victim machine. |
| T1583.004 Server |
GroupGALLIUM | GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM. |
| T1588.002 Tool |
GroupGALLIUM | GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.