ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1001×

36 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
GroupHEXANE

HEXANE has used a PowerShell-based keylogging tool to capture the window title.

T1016
System Network Configuration Discovery
GroupHEXANE

HEXANE has used Ping and `tracert` for network discovery.

T1016.001
Internet Connection Discovery
GroupHEXANE

HEXANE has used tools including BITSAdmin to test internet connectivity from compromised hosts.

T1018
Remote System Discovery
GroupHEXANE

HEXANE has used `net view` to enumerate domain machines.

T1021.001
Remote Desktop Protocol
GroupHEXANE

HEXANE has used remote desktop sessions for lateral movement.

T1027.010
Command Obfuscation
GroupHEXANE

HEXANE has used Base64-encoded scripts.

T1033
System Owner/User Discovery
GroupHEXANE

HEXANE has run `whoami` on compromised machines to identify the current user.

T1049
System Network Connections Discovery
GroupHEXANE

HEXANE has used netstat to monitor connections to specific ports.

T1053.005
Scheduled Task
GroupHEXANE

HEXANE has used a scheduled task to establish persistence for a keylogger.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1057
Process Discovery
GroupHEXANE

HEXANE has enumerated processes on targeted systems.

T1059.001
PowerShell
GroupHEXANE

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.005
Visual Basic
GroupHEXANE

HEXANE has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.

T1069.001
Local Groups
GroupHEXANE

HEXANE has run `net localgroup` to enumerate local groups.

T1082
System Information Discovery
GroupHEXANE

HEXANE has collected the hostname of a compromised machine.

T1102.002
Bidirectional Communication
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for C2.

T1105
Ingress Tool Transfer
GroupHEXANE

HEXANE has downloaded additional payloads and malicious scripts onto a compromised host.

T1110
Brute Force
GroupHEXANE

HEXANE has used brute force attacks to compromise valid credentials.

T1110.003
Password Spraying
GroupHEXANE

HEXANE has used password spraying attacks to obtain valid credentials.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1518
Software Discovery
GroupHEXANE

HEXANE has enumerated programs installed on an infected machine.

T1534
Internal Spearphishing
GroupHEXANE

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.

T1546.003
Windows Management Instrumentation Event Subscription
GroupHEXANE

HEXANE has used WMI event subscriptions for persistence.

T1555
Credentials from Password Stores
GroupHEXANE

HEXANE has run `cmdkey` on victim machines to identify stored credentials.

T1555.003
Credentials from Web Browsers
GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

T1567.002
Exfiltration to Cloud Storage
GroupHEXANE

HEXANE has used cloud services, including OneDrive, for data exfiltration.

T1583.001
Domains
GroupHEXANE

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.

T1583.002
DNS Server
GroupHEXANE

HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records.

T1585.001
Social Media Accounts
GroupHEXANE

HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.

T1585.002
Email Accounts
GroupHEXANE

HEXANE has established email accounts for use in domain registration including for ProtonMail addresses.

T1586.002
Email Accounts
GroupHEXANE

HEXANE has used compromised accounts to send spearphishing emails.

T1588.002
Tool
GroupHEXANE

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.

T1589
Gather Victim Identity Information
GroupHEXANE

HEXANE has identified specific potential victims at targeted organizations.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

T1591.004
Identify Roles
GroupHEXANE

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.

T1608.001
Upload Malware
GroupHEXANE

HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.