Real-world descriptions of how a group, tool or campaign used a technique.
59 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1007 System Service Discovery |
GroupChimera | Chimera has used |
| T1012 Query Registry |
GroupChimera | Chimera has queried Registry keys using |
| T1016 System Network Configuration Discovery |
GroupChimera | Chimera has used ipconfig, Ping, and |
| T1018 Remote System Discovery |
GroupChimera | Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment. |
| T1021.001 Remote Desktop Protocol |
GroupChimera | Chimera has used RDP to access targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
GroupChimera | Chimera has used Windows admin shares to move laterally. |
| T1021.006 Windows Remote Management |
GroupChimera | Chimera has used WinRM for lateral movement. |
| T1027.010 Command Obfuscation |
GroupChimera | Chimera has encoded PowerShell commands. |
| T1033 System Owner/User Discovery |
GroupChimera | Chimera has used the |
| T1036.005 Match Legitimate Resource Name or Location |
GroupChimera | Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1039 Data from Network Shared Drive |
GroupChimera | Chimera has collected data of interest from network shares. |
| T1041 Exfiltration Over C2 Channel |
GroupChimera | Chimera has used Cobalt Strike C2 beacons for data exfiltration. |
| T1046 Network Service Discovery |
GroupChimera | Chimera has used the |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1049 System Network Connections Discovery |
GroupChimera | Chimera has used |
| T1053.005 Scheduled Task |
GroupChimera | Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script |
| T1057 Process Discovery |
GroupChimera | Chimera has used |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
| T1059.003 Windows Command Shell |
GroupChimera | Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts. |
| T1069.001 Local Groups |
GroupChimera | Chimera has used |
| T1070.004 File Deletion |
GroupChimera | Chimera has performed file deletion to evade detection. |
| T1070.006 Timestomp |
GroupChimera | Chimera has used a Windows version of the Linux |
| T1071.001 Web Protocols |
GroupChimera | Chimera has used HTTPS for C2 communications. |
| T1071.004 DNS |
GroupChimera | Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic. |
| T1074.001 Local Data Staging |
GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
| T1074.002 Remote Data Staging |
GroupChimera | Chimera has staged stolen data on designated servers in the target environment. |
| T1078 Valid Accounts |
GroupChimera | Chimera has used a valid account to maintain persistence via scheduled task. |
| T1078.002 Domain Accounts |
GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| T1083 File and Directory Discovery |
GroupChimera | Chimera has utilized multiple commands to identify data of interest in file and directory listings. |
| T1087.001 Local Account |
GroupChimera | Chimera has used |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1105 Ingress Tool Transfer |
GroupChimera | Chimera has remotely copied tools and malware onto targeted systems. |
| T1106 Native API |
GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
| T1110.003 Password Spraying |
GroupChimera | Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts. |
| T1110.004 Credential Stuffing |
GroupChimera | Chimera has used credential stuffing against victim's remote services to obtain valid accounts. |
| T1111 Multi-Factor Authentication Interception |
GroupChimera | Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS. |
| T1114.001 Local Email Collection |
GroupChimera | Chimera has harvested data from victim's e-mail including through execution of |
| T1114.002 Remote Email Collection |
GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| T1119 Automated Collection |
GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| T1124 System Time Discovery |
GroupChimera | Chimera has used |
| T1133 External Remote Services |
GroupChimera | Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services. |
| T1135 Network Share Discovery |
GroupChimera | Chimera has used |
| T1201 Password Policy Discovery |
GroupChimera | Chimera has used the NtdsAudit utility to collect information related to accounts and passwords. |
| T1213.002 Sharepoint |
GroupChimera | Chimera has collected documents from the victim's SharePoint. |
| T1217 Browser Information Discovery |
GroupChimera | Chimera has used |
| T1482 Domain Trust Discovery |
GroupChimera | Chimera has |
| T1550.002 Pass the Hash |
GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| T1556.001 Domain Controller Authentication |
GroupChimera | Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential. |
| T1560.001 Archive via Utility |
GroupChimera | Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.