ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0117×

41 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFox Kitten

Fox Kitten has used prodump to dump credentials from LSASS.

T1003.003
NTDS
GroupFox Kitten

Fox Kitten has used Volume Shadow Copy to access credential information from NTDS.

T1005
Data from Local System
GroupFox Kitten

Fox Kitten has searched local system resources to access sensitive documents.

T1012
Query Registry
GroupFox Kitten

Fox Kitten has accessed Registry hives ntuser.dat and UserClass.dat.

T1018
Remote System Discovery
GroupFox Kitten

Fox Kitten has used Angry IP Scanner to detect remote systems.

T1021.001
Remote Desktop Protocol
GroupFox Kitten

Fox Kitten has used RDP to log in and move laterally in the target environment.

T1021.002
SMB/Windows Admin Shares
GroupFox Kitten

Fox Kitten has used valid accounts to access SMB shares.

T1021.004
SSH
GroupFox Kitten

Fox Kitten has used the PuTTY and Plink tools for lateral movement.

T1021.005
VNC
GroupFox Kitten

Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.

T1027.010
Command Obfuscation
GroupFox Kitten

Fox Kitten has base64 encoded scripts to avoid detection.

T1027.013
Encrypted/Encoded File
GroupFox Kitten

Fox Kitten has base64 encoded payloads to avoid detection.

T1036.004
Masquerade Task or Service
GroupFox Kitten

Fox Kitten has named the task for a reverse proxy lpupdate to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location
GroupFox Kitten

Fox Kitten has named binaries and configuration files svhost and dllhost respectively to appear legitimate.

T1039
Data from Network Shared Drive
GroupFox Kitten

Fox Kitten has searched network shares to access sensitive documents.

T1046
Network Service Discovery
GroupFox Kitten

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.

T1053.005
Scheduled Task
GroupFox Kitten

Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary.

T1059
Command and Scripting Interpreter
GroupFox Kitten

Fox Kitten has used a Perl reverse shell to communicate with C2.

T1059.001
PowerShell
GroupFox Kitten

Fox Kitten has used PowerShell scripts to access credential data.

T1059.003
Windows Command Shell
GroupFox Kitten

Fox Kitten has used cmd.exe likely as a password changing mechanism.

T1078
Valid Accounts
GroupFox Kitten

Fox Kitten has used valid credentials with various services during lateral movement.

T1083
File and Directory Discovery
GroupFox Kitten

Fox Kitten has used WizTree to obtain network files and directory listings.

T1087.001
Local Account
GroupFox Kitten

Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.

T1087.002
Domain Account
GroupFox Kitten

Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1102
Web Service
GroupFox Kitten

Fox Kitten has used Amazon Web Services to host C2.

T1105
Ingress Tool Transfer
GroupFox Kitten

Fox Kitten has downloaded additional tools including PsExec directly to endpoints.

T1110
Brute Force
GroupFox Kitten

Fox Kitten has brute forced RDP credentials.

T1136.001
Local Account
GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

T1190
Exploit Public-Facing Application
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances.

T1210
Exploitation of Remote Services
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

T1213.005
Messaging Applications
GroupFox Kitten

Fox Kitten has accessed victim security and IT environments and Microsoft Teams to mine valuable information.

T1217
Browser Information Discovery
GroupFox Kitten

Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.

T1505.003
Web Shell
GroupFox Kitten

Fox Kitten has installed web shells on compromised hosts to maintain access.

T1530
Data from Cloud Storage
GroupFox Kitten

Fox Kitten has obtained files from the victim's cloud storage instances.

T1546.008
Accessibility Features
GroupFox Kitten

Fox Kitten has used sticky keys to launch a command prompt.

T1552.001
Credentials In Files
GroupFox Kitten

Fox Kitten has accessed files to gain valid credentials.

T1555.005
Password Managers
GroupFox Kitten

Fox Kitten has used scripts to access credential information from the KeePass database.

T1560.001
Archive via Utility
GroupFox Kitten

Fox Kitten has used 7-Zip to archive data.

T1572
Protocol Tunneling
GroupFox Kitten

Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.

T1585
Establish Accounts
GroupFox Kitten

Fox Kitten has created KeyBase accounts to communicate with ransomware victims.

T1585.001
Social Media Accounts
GroupFox Kitten

Fox Kitten has used a Twitter account to communicate with ransomware victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.