Real-world descriptions of how a group, tool or campaign used a technique.
33 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupIndrik Spider | Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump. |
| T1007 System Service Discovery |
GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1012 Query Registry |
GroupIndrik Spider | Indrik Spider has used a service account to extract copies of the `Security` Registry hive. |
| T1018 Remote System Discovery |
GroupIndrik Spider | Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database. |
| T1021.001 Remote Desktop Protocol |
GroupIndrik Spider | Indrik Spider has used RDP for lateral movement. |
| T1021.004 SSH |
GroupIndrik Spider | Indrik Spider has used SSH for lateral movement. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupIndrik Spider | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1047 Windows Management Instrumentation |
GroupIndrik Spider | Indrik Spider has used WMIC to execute commands on remote computers. |
| T1059.001 PowerShell |
GroupIndrik Spider | Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.003 Windows Command Shell |
GroupIndrik Spider | Indrik Spider has used batch scripts on victim's machines. |
| T1059.007 JavaScript |
GroupIndrik Spider | Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1074.001 Local Data Staging |
GroupIndrik Spider | Indrik Spider has stored collected data in a .tmp file. |
| T1078 Valid Accounts |
GroupIndrik Spider | Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure. |
| T1078.002 Domain Accounts |
GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1105 Ingress Tool Transfer |
GroupIndrik Spider | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
| T1112 Modify Registry |
GroupIndrik Spider | Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities. |
| T1136 Create Account |
GroupIndrik Spider | Indrik Spider used |
| T1136.001 Local Account |
GroupIndrik Spider | Indrik Spider has created local system accounts and has added the accounts to privileged groups. |
| T1204.002 Malicious File |
GroupIndrik Spider | Indrik Spider has attempted to get users to click on a malicious zipped file. |
| T1484.001 Group Policy Modification |
GroupIndrik Spider | Indrik Spider has used Group Policy Objects to deploy batch scripts. |
| T1486 Data Encrypted for Impact |
GroupIndrik Spider | Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script. |
| T1489 Service Stop |
GroupIndrik Spider | Indrik Spider has used PsExec to stop services prior to the execution of ransomware. |
| T1552.001 Credentials In Files |
GroupIndrik Spider | Indrik Spider has searched files to obtain and exfiltrate credentials. |
| T1555.005 Password Managers |
GroupIndrik Spider | Indrik Spider has accessed and exported passwords from password managers. |
| T1558.003 Kerberoasting |
GroupIndrik Spider | Indrik Spider has conducted Kerberoasting attacks using a module from GitHub. |
| T1567.002 Exfiltration to Cloud Storage |
GroupIndrik Spider | Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware. |
| T1583 Acquire Infrastructure |
GroupIndrik Spider | Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments. |
| T1584.004 Server |
GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| T1585.002 Email Accounts |
GroupIndrik Spider | Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details. |
| T1587.001 Malware |
GroupIndrik Spider | Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker. |
| T1590 Gather Victim Network Information |
GroupIndrik Spider | Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc. |
| T1685 Disable or Modify Tools |
GroupIndrik Spider | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services. |
| T1685.005 Clear Windows Event Logs |
GroupIndrik Spider | Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.