Real-world descriptions of how a group, tool or campaign used a technique.
43 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMirrorFace | MirrorFace has dumped LSASS memory for credential access. |
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1005 Data from Local System |
GroupMirrorFace | MirrorFace gathered data and files of interest from victim's systems. |
| T1007 System Service Discovery |
GroupMirrorFace | MirrorFace has used Tasklist for discovery post compromise. |
| T1016 System Network Configuration Discovery |
GroupMirrorFace | MirrorFace has used ipconfig for reconnaissance. |
| T1018 Remote System Discovery |
GroupMirrorFace | MirrorFace has used Ping for system discovery. |
| T1021.001 Remote Desktop Protocol |
GroupMirrorFace | MirrorFace has used RDP to exfiltrate files of interest. |
| T1021.002 SMB/Windows Admin Shares |
GroupMirrorFace | MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1027.013 Encrypted/Encoded File |
GroupMirrorFace | MirrorFace has used Base64 encoded shellcode in infection chains to evade detection. |
| T1033 System Owner/User Discovery |
GroupMirrorFace | MirrorFace has used Windows native tools to enumerate user information. |
| T1036.008 Masquerade File Type |
GroupMirrorFace | MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files. |
| T1047 Windows Management Instrumentation |
GroupMirrorFace | MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupMirrorFace | MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration. |
| T1057 Process Discovery |
GroupMirrorFace | MirrorFace has used Tasklist on compromised hosts for discovery. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1059.005 Visual Basic |
GroupMirrorFace | MirrorFace has used remote templates with VBA code in malware infection chains. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1071.002 File Transfer Protocols |
GroupMirrorFace | MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer. |
| T1074.002 Remote Data Staging |
GroupMirrorFace | MirrorFace has gathered data and files of interest on a single victim machine. |
| T1082 System Information Discovery |
GroupMirrorFace | MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery. |
| T1083 File and Directory Discovery |
GroupMirrorFace | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions. |
| T1087.002 Domain Account |
GroupMirrorFace | MirrorFace has used native Windows tools to obtain domain user information. |
| T1090 Proxy |
GroupMirrorFace | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool. |
| T1114.001 Local Email Collection |
GroupMirrorFace | MirrorFace has exfiltrated stored emails from compromised hosts. |
| T1190 Exploit Public-Facing Application |
GroupMirrorFace | MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access. |
| T1204.002 Malicious File |
GroupMirrorFace | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution. |
| T1221 Template Injection |
GroupMirrorFace | MirrorFace has used remote template injection to retrieve malicious payloads from the C2. |
| T1482 Domain Trust Discovery |
GroupMirrorFace | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships. |
| T1553.002 Code Signing |
GroupMirrorFace | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed. |
| T1556.002 Password Filter DLL |
GroupMirrorFace | MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupMirrorFace | MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads. |
| T1566.002 Spearphishing Link |
GroupMirrorFace | MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation. |
| T1574.001 DLL |
GroupMirrorFace | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading. |
| T1587.001 Malware |
GroupMirrorFace | MirrorFace has created and continued to develop custom strains of malware including LODEINFO. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1591 Gather Victim Org Information |
GroupMirrorFace | MirrorFace has placed specific content in phishing emails to target members of particular political parties. |
| T1614.001 System Language Discovery |
GroupMirrorFace | MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings. |
| T1684.001 Impersonation |
GroupMirrorFace | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department. |
| T1685 Disable or Modify Tools |
GroupMirrorFace | MirrorFace has disabled Windows Defender in compromised environments. |
| T1685.005 Clear Windows Event Logs |
GroupMirrorFace | MirrorFace has deleted Windows event logs. |
| T1686.003 Windows Host Firewall |
GroupMirrorFace | MirrorFace can modify the system firewall to allow communication to certain ports. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.