Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupINC Ransom | INC Ransom has used RDP to move laterally. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1046 Network Service Discovery |
GroupINC Ransom | INC Ransom has used NETSCAN.EXE for internal reconnaissance. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1049 System Network Connections Discovery |
GroupINC Ransom | INC Ransom has used RDP to test network connections. |
| T1059.003 Windows Command Shell |
GroupINC Ransom | INC Ransom has used `cmd.exe` to launch malicious payloads. |
| T1069.002 Domain Groups |
GroupINC Ransom | INC Ransom has enumerated domain groups on targeted hosts. |
| T1070.004 File Deletion |
GroupINC Ransom | INC Ransom has uninstalled tools from compromised endpoints after use. |
| T1071 Application Layer Protocol |
GroupINC Ransom | INC Ransom has used valid accounts over RDP to connect to targeted systems. |
| T1074 Data Staged |
GroupINC Ransom | INC Ransom has staged data on compromised hosts prior to exfiltration. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1087.002 Domain Account |
GroupINC Ransom | INC Ransom has scanned for domain admin accounts in compromised environments. |
| T1105 Ingress Tool Transfer |
GroupINC Ransom | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. |
| T1135 Network Share Discovery |
GroupINC Ransom | INC Ransom has used Internet Explorer to view folders on other systems. |
| T1190 Exploit Public-Facing Application |
GroupINC Ransom | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1537 Transfer Data to Cloud Account |
GroupINC Ransom | INC Ransom has used Megasync to exfiltrate data to the cloud. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
| T1566 Phishing |
GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| T1569.002 Service Execution |
GroupINC Ransom | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`. |
| T1570 Lateral Tool Transfer |
GroupINC Ransom | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
| T1685 Disable or Modify Tools |
GroupINC Ransom | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.