Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.001 Local Account |
ToolPupy | Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc. |
| T1087.001 Local Account |
MalwareDuqu | The discovery modules used with Duqu can collect information on accounts and permissions. |
| T1087.002 Domain Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the domain. |
| T1087.002 Domain Account |
MalwarePOWRUNER | POWRUNER may collect user account information by running |
| T1087.002 Domain Account |
MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| T1087.002 Domain Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate domain accounts. |
| T1087.002 Domain Account |
MalwareRustyWater | RustyWater has gathered the domain membership of the victim machine’s user. |
| T1087.002 Domain Account |
MalwareBlackCat | BlackCat can utilize `net use` commands to identify domain users. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1087.002 Domain Account |
MalwareSykipot | Sykipot may use |
| T1087.002 Domain Account |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareBazar | Bazar has the ability to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareMgBot | MgBot includes modules for collecting information on Active Directory domain accounts. |
| T1087.002 Domain Account |
MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| T1087.002 Domain Account |
MalwareValak | Valak has the ability to enumerate domain admin accounts. |
| T1087.002 Domain Account |
MalwareBoomBox | BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. |
| T1087.002 Domain Account |
MalwareLAMEHUG | LAMEHUG can use dsquery to enumerate domain user information. |
| T1087.002 Domain Account |
MalwareIceApple | The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. |
| T1087.002 Domain Account |
MalwareQilin | Qilin can use PowerShell cmdlets to enumerate domain users. |
| T1087.002 Domain Account |
MalwareSoreFang | SoreFang can enumerate domain accounts via |
| T1087.002 Domain Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.002 Domain Account |
ToolNet | Net commands used with the |
| T1087.002 Domain Account |
ToolBloodHound | BloodHound can collect information about domain users, including identification of domain admin accounts. |
| T1087.002 Domain Account |
ToolSILENTTRINITY | SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information. |
| T1087.002 Domain Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.002 Domain Account |
Tooldsquery | dsquery can be used to gather information on user accounts within a domain. |
| T1087.002 Domain Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.002 Domain Account |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| T1087.002 Domain Account |
ToolCrackMapExec | CrackMapExec can enumerate the domain user accounts on a targeted system. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1087.003 Email Account |
MalwareTrickBot | TrickBot collects email addresses from Outlook. |
| T1087.003 Email Account |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects address book information from Outlook. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1087.003 Email Account |
MalwareGrandoreiro | Grandoreiro can parse Outlook .pst files to extract e-mail addresses. |
| T1087.003 Email Account |
MalwareBoomBox | BoomBox can execute an LDAP query to discover e-mail accounts for domain users. |
| T1087.003 Email Account |
MalwareLizar | Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird. |
| T1087.003 Email Account |
ToolRuler | Ruler can be used to enumerate Exchange users and dump the GAL. |
| T1087.003 Email Account |
ToolMailSniper | MailSniper can be used to obtain account names from Exchange and Office 365 using the |
| T1087.003 Email Account |
MalwareKali365 | Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments. |
| T1087.004 Cloud Account |
ToolPacu | Pacu can enumerate IAM users, roles, and groups. |
| T1087.004 Cloud Account |
ToolAADInternals | AADInternals can enumerate Azure AD users. |
| T1087.004 Cloud Account |
ToolROADTools | ROADTools can enumerate Azure AD users. |
| T1087.004 Cloud Account |
MalwareMini Shai-Hulud | Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity. |
| T1090 Proxy |
MalwarereGeorg | reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network. |
| T1090 Proxy |
MalwareUrsnif | Ursnif has used a peer-to-peer (P2P) network for C2. |
| T1090 Proxy |
MalwareRansomHub | RansomHub can use a proxy to connect to remote SFTP servers. |
| T1090 Proxy |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy. |
| T1090 Proxy |
MalwareHavoc | Havoc has the ability to route HTTP/S communications through designated proxies. |
| T1090 Proxy |
MalwareAuditCred | AuditCred can utilize proxy for communications. |
| T1090 Proxy |
MalwareRainyDay | RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.