Real-world descriptions of how a group, tool or campaign used a technique.
41 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFox Kitten | Fox Kitten has used prodump to dump credentials from LSASS. |
| T1003.003 NTDS |
GroupFox Kitten | Fox Kitten has used Volume Shadow Copy to access credential information from NTDS. |
| T1005 Data from Local System |
GroupFox Kitten | Fox Kitten has searched local system resources to access sensitive documents. |
| T1012 Query Registry |
GroupFox Kitten | Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat. |
| T1018 Remote System Discovery |
GroupFox Kitten | Fox Kitten has used Angry IP Scanner to detect remote systems. |
| T1021.001 Remote Desktop Protocol |
GroupFox Kitten | Fox Kitten has used RDP to log in and move laterally in the target environment. |
| T1021.002 SMB/Windows Admin Shares |
GroupFox Kitten | Fox Kitten has used valid accounts to access SMB shares. |
| T1021.004 SSH |
GroupFox Kitten | Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| T1021.005 VNC |
GroupFox Kitten | Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement. |
| T1027.010 Command Obfuscation |
GroupFox Kitten | Fox Kitten has base64 encoded scripts to avoid detection. |
| T1027.013 Encrypted/Encoded File |
GroupFox Kitten | Fox Kitten has base64 encoded payloads to avoid detection. |
| T1036.004 Masquerade Task or Service |
GroupFox Kitten | Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFox Kitten | Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate. |
| T1039 Data from Network Shared Drive |
GroupFox Kitten | Fox Kitten has searched network shares to access sensitive documents. |
| T1046 Network Service Discovery |
GroupFox Kitten | Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports. |
| T1053.005 Scheduled Task |
GroupFox Kitten | Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary. |
| T1059 Command and Scripting Interpreter |
GroupFox Kitten | Fox Kitten has used a Perl reverse shell to communicate with C2. |
| T1059.001 PowerShell |
GroupFox Kitten | Fox Kitten has used PowerShell scripts to access credential data. |
| T1059.003 Windows Command Shell |
GroupFox Kitten | Fox Kitten has used cmd.exe likely as a password changing mechanism. |
| T1078 Valid Accounts |
GroupFox Kitten | Fox Kitten has used valid credentials with various services during lateral movement. |
| T1083 File and Directory Discovery |
GroupFox Kitten | Fox Kitten has used WizTree to obtain network files and directory listings. |
| T1087.001 Local Account |
GroupFox Kitten | Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts. |
| T1087.002 Domain Account |
GroupFox Kitten | Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts. |
| T1090 Proxy |
GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| T1102 Web Service |
GroupFox Kitten | Fox Kitten has used Amazon Web Services to host C2. |
| T1105 Ingress Tool Transfer |
GroupFox Kitten | Fox Kitten has downloaded additional tools including PsExec directly to endpoints. |
| T1110 Brute Force |
GroupFox Kitten | Fox Kitten has brute forced RDP credentials. |
| T1136.001 Local Account |
GroupFox Kitten | Fox Kitten has created a local user account with administrator privileges. |
| T1190 Exploit Public-Facing Application |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances. |
| T1210 Exploitation of Remote Services |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| T1213.005 Messaging Applications |
GroupFox Kitten | Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information. |
| T1217 Browser Information Discovery |
GroupFox Kitten | Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets. |
| T1505.003 Web Shell |
GroupFox Kitten | Fox Kitten has installed web shells on compromised hosts to maintain access. |
| T1530 Data from Cloud Storage |
GroupFox Kitten | Fox Kitten has obtained files from the victim's cloud storage instances. |
| T1546.008 Accessibility Features |
GroupFox Kitten | Fox Kitten has used sticky keys to launch a command prompt. |
| T1552.001 Credentials In Files |
GroupFox Kitten | Fox Kitten has accessed files to gain valid credentials. |
| T1555.005 Password Managers |
GroupFox Kitten | Fox Kitten has used scripts to access credential information from the KeePass database. |
| T1560.001 Archive via Utility |
GroupFox Kitten | Fox Kitten has used 7-Zip to archive data. |
| T1572 Protocol Tunneling |
GroupFox Kitten | Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion. |
| T1585 Establish Accounts |
GroupFox Kitten | Fox Kitten has created KeyBase accounts to communicate with ransomware victims. |
| T1585.001 Social Media Accounts |
GroupFox Kitten | Fox Kitten has used a Twitter account to communicate with ransomware victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.