Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1068 Exploitation for Privilege Escalation |
GroupAPT33 | APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1068 Exploitation for Privilege Escalation |
MalwareStuxnet | Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines. |
| T1068 Exploitation for Privilege Escalation |
MalwareCosmicDuke | CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398. |
| T1068 Exploitation for Privilege Escalation |
MalwareHildegard | Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1068 Exploitation for Privilege Escalation |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service. |
| T1068 Exploitation for Privilege Escalation |
MalwareProLock | ProLock can use CVE-2019-0859 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
MalwareInvisiMole | InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareSiloscape | Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host. |
| T1068 Exploitation for Privilege Escalation |
MalwareRemsec | Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareEmbargo | Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.” |
| T1068 Exploitation for Privilege Escalation |
MalwareJHUHUGIT | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwarePandora | Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1068 Exploitation for Privilege Escalation |
MalwareWingbird | Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareCarberp | Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
MalwareXCSSET | XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1068 Exploitation for Privilege Escalation |
MalwareZox | Zox has the ability to leverage local and remote exploits to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
ToolEmpire | Empire can exploit vulnerabilities such as MS16-032 and MS16-135. |
| T1068 Exploitation for Privilege Escalation |
ToolPoshC2 | PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099. |
| T1068 Exploitation for Privilege Escalation |
MalwareZeroCleare | ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver. |
| T1069 Permission Groups Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell. |
| T1069 Permission Groups Discovery |
GroupAPT3 | APT3 has a tool that can enumerate the permissions associated with Windows groups. |
| T1069 Permission Groups Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery. |
| T1069 Permission Groups Discovery |
GroupAPT41 | APT41 used |
| T1069 Permission Groups Discovery |
GroupScattered Spider | Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| T1069 Permission Groups Discovery |
GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1069 Permission Groups Discovery |
GroupFIN13 | FIN13 has enumerated all users and roles from a victim's main treasury system. |
| T1069 Permission Groups Discovery |
MalwareTrickBot | TrickBot can identify the groups the user on a compromised host belongs to. |
| T1069 Permission Groups Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about groups. |
| T1069 Permission Groups Discovery |
MalwareSiloscape | Siloscape checks for Kubernetes node permissions. |
| T1069 Permission Groups Discovery |
MalwareIcedID | IcedID has the ability to identify Workgroup membership. |
| T1069 Permission Groups Discovery |
MalwareCarbon | Carbon uses the |
| T1069 Permission Groups Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local privileges for the infected host. |
| T1069.001 Local Groups |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| T1069.001 Local Groups |
CampaignC0015 | During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights. |
| T1069.001 Local Groups |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance. |
| T1069.001 Local Groups |
CampaignOperation Wocao | During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group. |
| T1069.001 Local Groups |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: |
| T1069.001 Local Groups |
GroupVolt Typhoon | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts. |
| T1069.001 Local Groups |
GroupOilRig | OilRig has used |
| T1069.001 Local Groups |
GroupTurla | Turla has used |
| T1069.001 Local Groups |
GroupChimera | Chimera has used |
| T1069.001 Local Groups |
GroupTonto Team | Tonto Team has used the |
| T1069.001 Local Groups |
GroupHEXANE | HEXANE has run `net localgroup` to enumerate local groups. |
| T1069.001 Local Groups |
MalwarePOWRUNER | POWRUNER may collect local group information by running |
| T1069.001 Local Groups |
MalwareEmissary | Emissary has the capability to execute the command |
| T1069.001 Local Groups |
MalwareGomir | Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments. |
| T1069.001 Local Groups |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| T1069.001 Local Groups |
MalwareKazuar | Kazuar gathers information about local groups and members. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.