ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1087.001
Local Account
ToolPupy

Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc.

T1087.001
Local Account
MalwareDuqu

The discovery modules used with Duqu can collect information on accounts and permissions.

T1087.002
Domain Account
MalwareStuxnet

Stuxnet enumerates user accounts of the domain.

T1087.002
Domain Account
MalwarePOWRUNER

POWRUNER may collect user account information by running net user /domain or a series of other commands on a victim.

T1087.002
Domain Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account
MalwareDUSTTRAP

DUSTTRAP can enumerate domain accounts.

T1087.002
Domain Account
MalwareRustyWater

RustyWater has gathered the domain membership of the victim machine’s user.

T1087.002
Domain Account
MalwareBlackCat

BlackCat can utilize `net use` commands to identify domain users.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1087.002
Domain Account
MalwareSykipot

Sykipot may use net group "domain admins" /domain to display accounts in the "domain admins" permissions group and net localgroup "administrators" to list local system administrator group membership.

T1087.002
Domain Account
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1087.002
Domain Account
MalwareMgBot

MgBot includes modules for collecting information on Active Directory domain accounts.

T1087.002
Domain Account
MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

T1087.002
Domain Account
MalwareValak

Valak has the ability to enumerate domain admin accounts.

T1087.002
Domain Account
MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.002
Domain Account
MalwareLAMEHUG

LAMEHUG can use dsquery to enumerate domain user information.

T1087.002
Domain Account
MalwareIceApple

The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server.

T1087.002
Domain Account
MalwareQilin

Qilin can use PowerShell cmdlets to enumerate domain users.

T1087.002
Domain Account
MalwareSoreFang

SoreFang can enumerate domain accounts via net.exe user /domain.

T1087.002
Domain Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1087.002
Domain Account
ToolNet

Net commands used with the /domain flag can be used to gather information about and manipulate user accounts on the current domain.

T1087.002
Domain Account
ToolBloodHound

BloodHound can collect information about domain users, including identification of domain admin accounts.

T1087.002
Domain Account
ToolSILENTTRINITY

SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information.

T1087.002
Domain Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.002
Domain Account
Tooldsquery

dsquery can be used to gather information on user accounts within a domain.

T1087.002
Domain Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.002
Domain Account
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

T1087.002
Domain Account
ToolCrackMapExec

CrackMapExec can enumerate the domain user accounts on a targeted system.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1087.003
Email Account
MalwareTrickBot

TrickBot collects email addresses from Outlook.

T1087.003
Email Account
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects address book information from Outlook.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1087.003
Email Account
MalwareGrandoreiro

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.

T1087.003
Email Account
MalwareBoomBox

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1087.003
Email Account
MalwareLizar

Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird.

T1087.003
Email Account
ToolRuler

Ruler can be used to enumerate Exchange users and dump the GAL.

T1087.003
Email Account
ToolMailSniper

MailSniper can be used to obtain account names from Exchange and Office 365 using the Get-GlobalAddressList cmdlet.

T1087.003
Email Account
MalwareKali365

Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.

T1087.004
Cloud Account
ToolPacu

Pacu can enumerate IAM users, roles, and groups.

T1087.004
Cloud Account
ToolAADInternals

AADInternals can enumerate Azure AD users.

T1087.004
Cloud Account
ToolROADTools

ROADTools can enumerate Azure AD users.

T1087.004
Cloud Account
MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated cloud accounts and subscriptions accessible to the targeted identity.

T1090
Proxy
MalwarereGeorg

reGeorg can establish an HTTP or SOCKS proxy to tunnel data in and out of a network.

T1090
Proxy
MalwareUrsnif

Ursnif has used a peer-to-peer (P2P) network for C2.

T1090
Proxy
MalwareRansomHub

RansomHub can use a proxy to connect to remote SFTP servers.

T1090
Proxy
MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy.

T1090
Proxy
MalwareHavoc

Havoc has the ability to route HTTP/S communications through designated proxies.

T1090
Proxy
MalwareAuditCred

AuditCred can utilize proxy for communications.

T1090
Proxy
MalwareRainyDay

RainyDay can use proxy tools including boost_proxy_client for reverse proxy functionality.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.