ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1016×

53 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN13

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

T1003.002
Security Account Manager
GroupFIN13

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

T1003.003
NTDS
GroupFIN13

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016.001
Internet Connection Discovery
GroupFIN13

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

T1021.001
Remote Desktop Protocol
GroupFIN13

FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupFIN13

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.

T1021.004
SSH
GroupFIN13

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.

T1021.006
Windows Remote Management
GroupFIN13

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.

T1036
Masquerading
GroupFIN13

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

T1036.004
Masquerade Task or Service
GroupFIN13

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.

T1036.005
Match Legitimate Resource Name or Location
GroupFIN13

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.

T1046
Network Service Discovery
GroupFIN13

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

T1049
System Network Connections Discovery
GroupFIN13

FIN13 has used `netstat` and other net commands for network reconnaissance efforts.

T1053.005
Scheduled Task
GroupFIN13

FIN13 has created scheduled tasks in the `C:\Windows` directory of the compromised network.

T1056.001
Keylogging
GroupFIN13

FIN13 has logged the keystrokes of victims to escalate privileges.

T1059.001
PowerShell
GroupFIN13

FIN13 has used PowerShell commands to obtain DNS data from a compromised network.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1059.005
Visual Basic
GroupFIN13

FIN13 has used VBS scripts for code execution on comrpomised machines.

T1069
Permission Groups Discovery
GroupFIN13

FIN13 has enumerated all users and roles from a victim's main treasury system.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1074.001
Local Data Staging
GroupFIN13

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.

T1078.001
Default Accounts
GroupFIN13

FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access.

T1082
System Information Discovery
GroupFIN13

FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information.

T1083
File and Directory Discovery
GroupFIN13

FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network.

T1087
Account Discovery
GroupFIN13

FIN13 has enumerated all users and their roles from a victim's main treasury system.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

T1090.001
Internal Proxy
GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

T1098.007
Additional Local or Domain Groups
GroupFIN13

FIN13 has assigned newly created accounts the sysadmin role to maintain persistence.

T1105
Ingress Tool Transfer
GroupFIN13

FIN13 has downloaded additional tools and malware to compromised systems.

T1133
External Remote Services
GroupFIN13

FIN13 has gained access to compromised environments via remote access services such as the corporate virtual private network (VPN).

T1134.003
Make and Impersonate Token
GroupFIN13

FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

T1136.001
Local Account
GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

T1140
Deobfuscate/Decode Files or Information
GroupFIN13

FIN13 has utilized `certutil` to decode base64 encoded versions of custom malware.

T1190
Exploit Public-Facing Application
GroupFIN13

FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access.

T1505.003
Web Shell
GroupFIN13

FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN13

FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence.

T1550.002
Pass the Hash
GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

T1552.001
Credentials In Files
GroupFIN13

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.

T1556
Modify Authentication Process
GroupFIN13

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.

T1560.001
Archive via Utility
GroupFIN13

FIN13 has compressed the dump output of compromised credentials with a 7zip binary.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1565
Data Manipulation
GroupFIN13

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.

T1572
Protocol Tunneling
GroupFIN13

FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets.

T1574.001
DLL
GroupFIN13

FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).

T1587.001
Malware
GroupFIN13

FIN13 has utilized custom malware to maintain persistence in a compromised environment.

T1588.002
Tool
GroupFIN13

FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.