ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0114×

59 examples

TechniqueUsed byProcedure example
T1567.002
Exfiltration to Cloud Storage
GroupChimera

Chimera has exfiltrated stolen data to OneDrive accounts.

T1569.002
Service Execution
GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

T1570
Lateral Tool Transfer
GroupChimera

Chimera has copied tools between compromised hosts using SMB.

T1572
Protocol Tunneling
GroupChimera

Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS.

T1574.001
DLL
GroupChimera

Chimera has used side loading to place malicious DLLs in memory.

T1588.002
Tool
GroupChimera

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.

T1589.001
Credentials
GroupChimera

Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks.

T1680
Local Storage Discovery
GroupChimera

Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information.

T1685.005
Clear Windows Event Logs
GroupChimera

Chimera has cleared event logs on compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.