Real-world descriptions of how a group, tool or campaign used a technique.
81 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupVolt Typhoon | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1006 Direct Volume Access |
GroupVolt Typhoon | Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| T1007 System Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used `net start` to list running services. |
| T1010 Application Window Discovery |
GroupVolt Typhoon | Volt Typhoon has collected window title information from compromised systems. |
| T1012 Query Registry |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1016 System Network Configuration Discovery |
GroupVolt Typhoon | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1016.001 Internet Connection Discovery |
GroupVolt Typhoon | Volt Typhoon has employed Ping to check network connectivity. |
| T1018 Remote System Discovery |
GroupVolt Typhoon | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1021.001 Remote Desktop Protocol |
GroupVolt Typhoon | Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges. |
| T1027.002 Software Packing |
GroupVolt Typhoon | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVolt Typhoon | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.008 Masquerade File Type |
GroupVolt Typhoon | Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension. |
| T1046 Network Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1049 System Network Connections Discovery |
GroupVolt Typhoon | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections. |
| T1056.001 Keylogging |
GroupVolt Typhoon | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1059.004 Unix Shell |
GroupVolt Typhoon | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh). |
| T1068 Exploitation for Privilege Escalation |
GroupVolt Typhoon | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services. |
| T1069 Permission Groups Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery. |
| T1069.001 Local Groups |
GroupVolt Typhoon | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts. |
| T1069.002 Domain Groups |
GroupVolt Typhoon | Volt Typhoon has run `net group` in compromised environments to discover domain groups. |
| T1070.004 File Deletion |
GroupVolt Typhoon | Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`. |
| T1070.007 Clear Network Connection History and Configurations |
GroupVolt Typhoon | Volt Typhoon has inspected server logs to remove their IPs. |
| T1074 Data Staged |
GroupVolt Typhoon | Volt Typhoon has staged collected data in password-protected archives. |
| T1074.001 Local Data Staging |
GroupVolt Typhoon | Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory. |
| T1078 Valid Accounts |
GroupVolt Typhoon | Volt Typhoon relies primarily on valid credentials for persistence. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1083 File and Directory Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings. |
| T1087.001 Local Account |
GroupVolt Typhoon | Volt Typhoon has executed `net user` and `quser` to enumerate local account information. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1090.003 Multi-hop Proxy |
GroupVolt Typhoon | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure. |
| T1105 Ingress Tool Transfer |
GroupVolt Typhoon | Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder. |
| T1112 Modify Registry |
GroupVolt Typhoon | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG). |
| T1113 Screen Capture |
GroupVolt Typhoon | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries. |
| T1120 Peripheral Device Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained victim's screen dimension and display device information. |
| T1124 System Time Discovery |
GroupVolt Typhoon | Volt Typhoon has obtained the victim's system timezone. |
| T1133 External Remote Services |
GroupVolt Typhoon | Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions. |
| T1140 Deobfuscate/Decode Files or Information |
GroupVolt Typhoon | Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil. |
| T1190 Exploit Public-Facing Application |
GroupVolt Typhoon | Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco. |
| T1217 Browser Information Discovery |
GroupVolt Typhoon | Volt Typhoon has targeted the browsing history of network administrators. |
| T1218 System Binary Proxy Execution |
GroupVolt Typhoon | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks. |
| T1497.001 System Checks |
GroupVolt Typhoon | Volt Typhoon has run system checks to determine if they were operating in a virtualized environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.