ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1017×

81 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupVolt Typhoon

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.

T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1006
Direct Volume Access
GroupVolt Typhoon

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

T1007
System Service Discovery
GroupVolt Typhoon

Volt Typhoon has used `net start` to list running services.

T1010
Application Window Discovery
GroupVolt Typhoon

Volt Typhoon has collected window title information from compromised systems.

T1012
Query Registry
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1016
System Network Configuration Discovery
GroupVolt Typhoon

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.

T1016.001
Internet Connection Discovery
GroupVolt Typhoon

Volt Typhoon has employed Ping to check network connectivity.

T1018
Remote System Discovery
GroupVolt Typhoon

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1021.001
Remote Desktop Protocol
GroupVolt Typhoon

Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.

T1027.002
Software Packing
GroupVolt Typhoon

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1036.008
Masquerade File Type
GroupVolt Typhoon

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

T1046
Network Service Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1049
System Network Connections Discovery
GroupVolt Typhoon

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.

T1056.001
Keylogging
GroupVolt Typhoon

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1059.004
Unix Shell
GroupVolt Typhoon

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).

T1068
Exploitation for Privilege Escalation
GroupVolt Typhoon

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.

T1069
Permission Groups Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.

T1069.001
Local Groups
GroupVolt Typhoon

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.

T1069.002
Domain Groups
GroupVolt Typhoon

Volt Typhoon has run `net group` in compromised environments to discover domain groups.

T1070.004
File Deletion
GroupVolt Typhoon

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.

T1070.007
Clear Network Connection History and Configurations
GroupVolt Typhoon

Volt Typhoon has inspected server logs to remove their IPs.

T1074
Data Staged
GroupVolt Typhoon

Volt Typhoon has staged collected data in password-protected archives.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1078
Valid Accounts
GroupVolt Typhoon

Volt Typhoon relies primarily on valid credentials for persistence.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1083
File and Directory Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings.

T1087.001
Local Account
GroupVolt Typhoon

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1090.003
Multi-hop Proxy
GroupVolt Typhoon

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.

T1105
Ingress Tool Transfer
GroupVolt Typhoon

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.

T1112
Modify Registry
GroupVolt Typhoon

Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).

T1113
Screen Capture
GroupVolt Typhoon

Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.

T1120
Peripheral Device Discovery
GroupVolt Typhoon

Volt Typhoon has obtained victim's screen dimension and display device information.

T1124
System Time Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system timezone.

T1133
External Remote Services
GroupVolt Typhoon

Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions.

T1140
Deobfuscate/Decode Files or Information
GroupVolt Typhoon

Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil.

T1190
Exploit Public-Facing Application
GroupVolt Typhoon

Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco.

T1217
Browser Information Discovery
GroupVolt Typhoon

Volt Typhoon has targeted the browsing history of network administrators.

T1218
System Binary Proxy Execution
GroupVolt Typhoon

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.

T1497.001
System Checks
GroupVolt Typhoon

Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.