Real-world descriptions of how a group, tool or campaign used a technique.
36 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
GroupHEXANE | HEXANE has used a PowerShell-based keylogging tool to capture the window title. |
| T1016 System Network Configuration Discovery |
GroupHEXANE | |
| T1016.001 Internet Connection Discovery |
GroupHEXANE | HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts. |
| T1018 Remote System Discovery |
GroupHEXANE | HEXANE has used `net view` to enumerate domain machines. |
| T1021.001 Remote Desktop Protocol |
GroupHEXANE | HEXANE has used remote desktop sessions for lateral movement. |
| T1027.010 Command Obfuscation |
GroupHEXANE | HEXANE has used Base64-encoded scripts. |
| T1033 System Owner/User Discovery |
GroupHEXANE | HEXANE has run `whoami` on compromised machines to identify the current user. |
| T1049 System Network Connections Discovery |
GroupHEXANE | HEXANE has used netstat to monitor connections to specific ports. |
| T1053.005 Scheduled Task |
GroupHEXANE | HEXANE has used a scheduled task to establish persistence for a keylogger. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1057 Process Discovery |
GroupHEXANE | HEXANE has enumerated processes on targeted systems. |
| T1059.001 PowerShell |
GroupHEXANE | HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts. |
| T1059.005 Visual Basic |
GroupHEXANE | HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger. |
| T1069.001 Local Groups |
GroupHEXANE | HEXANE has run `net localgroup` to enumerate local groups. |
| T1082 System Information Discovery |
GroupHEXANE | HEXANE has collected the hostname of a compromised machine. |
| T1102.002 Bidirectional Communication |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for C2. |
| T1105 Ingress Tool Transfer |
GroupHEXANE | HEXANE has downloaded additional payloads and malicious scripts onto a compromised host. |
| T1110 Brute Force |
GroupHEXANE | HEXANE has used brute force attacks to compromise valid credentials. |
| T1110.003 Password Spraying |
GroupHEXANE | HEXANE has used password spraying attacks to obtain valid credentials. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1518 Software Discovery |
GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
| T1534 Internal Spearphishing |
GroupHEXANE | HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupHEXANE | HEXANE has used WMI event subscriptions for persistence. |
| T1555 Credentials from Password Stores |
GroupHEXANE | HEXANE has run `cmdkey` on victim machines to identify stored credentials. |
| T1555.003 Credentials from Web Browsers |
GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for data exfiltration. |
| T1583.001 Domains |
GroupHEXANE | HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization. |
| T1583.002 DNS Server |
GroupHEXANE | HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records. |
| T1585.001 Social Media Accounts |
GroupHEXANE | HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers. |
| T1585.002 Email Accounts |
GroupHEXANE | HEXANE has established email accounts for use in domain registration including for ProtonMail addresses. |
| T1586.002 Email Accounts |
GroupHEXANE | HEXANE has used compromised accounts to send spearphishing emails. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
| T1589 Gather Victim Identity Information |
GroupHEXANE | HEXANE has identified specific potential victims at targeted organizations. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| T1591.004 Identify Roles |
GroupHEXANE | HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting. |
| T1608.001 Upload Malware |
GroupHEXANE | HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.