Real-world descriptions of how a group, tool or campaign used a technique.
26 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupPlay | Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory. |
| T1016 System Network Configuration Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to enumerate network information. |
| T1018 Remote System Discovery |
GroupPlay | Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupPlay | Play has used Cobalt Strike to move laterally via SMB. |
| T1027.010 Command Obfuscation |
GroupPlay | Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts. |
| T1030 Data Transfer Size Limits |
GroupPlay | Play has split victims' files into chunks for exfiltration. |
| T1048 Exfiltration Over Alternative Protocol |
GroupPlay | Play has used WinSCP to exfiltrate data to actor-controlled accounts. |
| T1057 Process Discovery |
GroupPlay | Play has used the information stealer Grixba to check for a list of security processes. |
| T1059.001 PowerShell |
GroupPlay | Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender. |
| T1059.003 Windows Command Shell |
GroupPlay | Play has used a batch script to remove indicators of its presence on compromised hosts. |
| T1070.004 File Deletion |
GroupPlay | Play has used tools including Wevtutil to remove malicious files from compromised hosts. |
| T1078 Valid Accounts |
GroupPlay | Play has used valid VPN accounts to achieve initial access. |
| T1078.002 Domain Accounts |
GroupPlay | Play has used valid domain accounts for access. |
| T1078.003 Local Accounts |
GroupPlay | Play has used valid local accounts to gain initial access. |
| T1082 System Information Discovery |
GroupPlay | Play has leveraged tools to enumerate system information. |
| T1083 File and Directory Discovery |
GroupPlay | Play has used the Grixba information stealer to list security files and processes. |
| T1105 Ingress Tool Transfer |
GroupPlay | Play has used Cobalt Strike to download files to compromised machines. |
| T1133 External Remote Services |
GroupPlay | Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access. |
| T1190 Exploit Public-Facing Application |
GroupPlay | Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange. |
| T1518.001 Security Software Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to scan for anti-virus software. |
| T1560.001 Archive via Utility |
GroupPlay | Play has used WinRAR to compress files prior to exfiltration. |
| T1587.001 Malware |
GroupPlay | |
| T1588.002 Tool |
GroupPlay | Play has used multiple tools for discovery and defense evasion purposes on compromised hosts. |
| T1657 Financial Theft |
GroupPlay | Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks. |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.