ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1017×

81 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
GroupVolt Typhoon

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.

T1518
Software Discovery
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems for information on installed software.

T1552
Unsecured Credentials
GroupVolt Typhoon

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.

T1552.004
Private Keys
GroupVolt Typhoon

Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser.

T1555
Credentials from Password Stores
GroupVolt Typhoon

Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.

T1555.003
Credentials from Web Browsers
GroupVolt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.

T1560.001
Archive via Utility
GroupVolt Typhoon

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.

T1570
Lateral Tool Transfer
GroupVolt Typhoon

Volt Typhoon has copied web shells between servers in targeted environments.

T1573.001
Symmetric Cryptography
GroupVolt Typhoon

Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications.

T1584.003
Virtual Private Server
GroupVolt Typhoon

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.

T1584.004
Server
GroupVolt Typhoon

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.

T1584.005
Botnet
GroupVolt Typhoon

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.

T1584.008
Network Devices
GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

T1587.004
Exploits
GroupVolt Typhoon

Volt Typhoon has exploited zero-day vulnerabilities for initial access.

T1588.002
Tool
GroupVolt Typhoon

Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2.

T1588.006
Vulnerabilities
GroupVolt Typhoon

Volt Typhoon has used publicly available exploit code for initial access.

T1589
Gather Victim Identity Information
GroupVolt Typhoon

Volt Typhoon has gathered victim identify information during pre-compromise reconnaissance.

T1589.002
Email Addresses
GroupVolt Typhoon

Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.

T1590
Gather Victim Network Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.

T1590.004
Network Topology
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.

T1590.006
Network Security Appliances
GroupVolt Typhoon

Volt Typhoon has identified target network security measures as part of pre-compromise reconnaissance.

T1591
Gather Victim Org Information
GroupVolt Typhoon

Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.

T1591.004
Identify Roles
GroupVolt Typhoon

Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations.

T1592
Gather Victim Host Information
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance for victim host information.

T1593
Search Open Websites/Domains
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise web searches for victim information.

T1594
Search Victim-Owned Websites
GroupVolt Typhoon

Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites.

T1596.005
Scan Databases
GroupVolt Typhoon

Volt Typhoon has used FOFA, Shodan, and Censys to search for exposed victim infrastructure.

T1614
System Location Discovery
GroupVolt Typhoon

Volt Typhoon has obtained the victim's system current location.

T1654
Log Enumeration
GroupVolt Typhoon

Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

T1685.005
Clear Windows Event Logs
GroupVolt Typhoon

Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.