Real-world descriptions of how a group, tool or campaign used a technique.
64 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupWizard Spider | Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne. |
| T1003.002 Security Account Manager |
GroupWizard Spider | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.003 NTDS |
GroupWizard Spider | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1005 Data from Local System |
GroupWizard Spider | Wizard Spider has collected data from a compromised host prior to exfiltration. |
| T1016 System Network Configuration Discovery |
GroupWizard Spider | Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1021 Remote Services |
GroupWizard Spider | Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares. |
| T1021.001 Remote Desktop Protocol |
GroupWizard Spider | Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively. |
| T1021.002 SMB/Windows Admin Shares |
GroupWizard Spider | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1021.006 Windows Remote Management |
GroupWizard Spider | Wizard Spider has used Window Remote Management to move laterally through a victim network. |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1033 System Owner/User Discovery |
GroupWizard Spider | Wizard Spider has used "whoami" to identify the local user and their privileges. |
| T1036.004 Masquerade Task or Service |
GroupWizard Spider | Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries. |
| T1041 Exfiltration Over C2 Channel |
GroupWizard Spider | Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1053.005 Scheduled Task |
GroupWizard Spider | Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware. |
| T1055 Process Injection |
GroupWizard Spider | Wizard Spider has used process injection to execute payloads to escalate privileges. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1059.003 Windows Command Shell |
GroupWizard Spider | Wizard Spider has used `cmd.exe` to execute commands on a victim's machine. |
| T1070.004 File Deletion |
GroupWizard Spider | Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use. |
| T1071.001 Web Protocols |
GroupWizard Spider | Wizard Spider has used HTTP for network communications. |
| T1074 Data Staged |
GroupWizard Spider | Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules. |
| T1074.001 Local Data Staging |
GroupWizard Spider | Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration. |
| T1078 Valid Accounts |
GroupWizard Spider | Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers. |
| T1078.002 Domain Accounts |
GroupWizard Spider | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network. |
| T1082 System Information Discovery |
GroupWizard Spider | Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory. |
| T1087.002 Domain Account |
GroupWizard Spider | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data. |
| T1105 Ingress Tool Transfer |
GroupWizard Spider | Wizard Spider can transfer malicious payloads such as ransomware to compromised machines. |
| T1112 Modify Registry |
GroupWizard Spider | Wizard Spider has modified the Registry key |
| T1133 External Remote Services |
GroupWizard Spider | Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure. |
| T1135 Network Share Discovery |
GroupWizard Spider | Wizard Spider has used the “net view” command to locate mapped network shares. |
| T1136.001 Local Account |
GroupWizard Spider | Wizard Spider has created local administrator accounts to maintain persistence in compromised networks. |
| T1136.002 Domain Account |
GroupWizard Spider | Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence. |
| T1197 BITS Jobs |
GroupWizard Spider | Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine. |
| T1204.001 Malicious Link |
GroupWizard Spider | Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing. |
| T1204.002 Malicious File |
GroupWizard Spider | Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1218.011 Rundll32 |
GroupWizard Spider | Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV. |
| T1222.001 Windows Permissions |
GroupWizard Spider | Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders. |
| T1489 Service Stop |
GroupWizard Spider | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption. |
| T1490 Inhibit System Recovery |
GroupWizard Spider | Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin. |
| T1518.001 Security Software Discovery |
GroupWizard Spider | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine. |
| T1518.002 Backup Software Discovery |
GroupWizard Spider | Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine. |
| T1543.003 Windows Service |
GroupWizard Spider | Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWizard Spider | Wizard Spider has established persistence via the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupWizard Spider | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. |
| T1550.002 Pass the Hash |
GroupWizard Spider | Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally. |
| T1552.006 Group Policy Preferences |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.