ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G1040×

26 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupPlay

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.

T1016
System Network Configuration Discovery
GroupPlay

Play has used the information-stealing tool Grixba to enumerate network information.

T1018
Remote System Discovery
GroupPlay

Play has used tools such as AdFind, Nltest, and BloodHound to enumerate shares and hostnames on compromised networks.

T1021.002
SMB/Windows Admin Shares
GroupPlay

Play has used Cobalt Strike to move laterally via SMB.

T1027.010
Command Obfuscation
GroupPlay

Play has used Base64-encoded PowerShell scripts for post exploit activities on compromised hosts.

T1030
Data Transfer Size Limits
GroupPlay

Play has split victims' files into chunks for exfiltration.

T1048
Exfiltration Over Alternative Protocol
GroupPlay

Play has used WinSCP to exfiltrate data to actor-controlled accounts.

T1057
Process Discovery
GroupPlay

Play has used the information stealer Grixba to check for a list of security processes.

T1059.001
PowerShell
GroupPlay

Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender.

T1059.003
Windows Command Shell
GroupPlay

Play has used a batch script to remove indicators of its presence on compromised hosts.

T1070.004
File Deletion
GroupPlay

Play has used tools including Wevtutil to remove malicious files from compromised hosts.

T1078
Valid Accounts
GroupPlay

Play has used valid VPN accounts to achieve initial access.

T1078.002
Domain Accounts
GroupPlay

Play has used valid domain accounts for access.

T1078.003
Local Accounts
GroupPlay

Play has used valid local accounts to gain initial access.

T1082
System Information Discovery
GroupPlay

Play has leveraged tools to enumerate system information.

T1083
File and Directory Discovery
GroupPlay

Play has used the Grixba information stealer to list security files and processes.

T1105
Ingress Tool Transfer
GroupPlay

Play has used Cobalt Strike to download files to compromised machines.

T1133
External Remote Services
GroupPlay

Play has used Remote Desktop Protocol (RDP) and Virtual Private Networks (VPN) for initial access.

T1190
Exploit Public-Facing Application
GroupPlay

Play has exploited known vulnerabilities for initial access including CVE-2018-13379 and CVE-2020-12812 in FortiOS and CVE-2022-41082 and CVE-2022-41040 ("ProxyNotShell") in Microsoft Exchange.

T1518.001
Security Software Discovery
GroupPlay

Play has used the information-stealing tool Grixba to scan for anti-virus software.

T1560.001
Archive via Utility
GroupPlay

Play has used WinRAR to compress files prior to exfiltration.

T1587.001
Malware
GroupPlay

Play developed and employ Playcrypt ransomware.

T1588.002
Tool
GroupPlay

Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.

T1657
Financial Theft
GroupPlay

Play demands ransom payments from victims to unencrypt filesystems and to not publish sensitive data exfiltrated from victim networks.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.