ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1068
Exploitation for Privilege Escalation
MalwareStuxnet

Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines.

T1068
Exploitation for Privilege Escalation
MalwareCosmicDuke

CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398.

T1068
Exploitation for Privilege Escalation
MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1068
Exploitation for Privilege Escalation
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.

T1068
Exploitation for Privilege Escalation
MalwareProLock

ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareSiloscape

Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host.

T1068
Exploitation for Privilege Escalation
MalwareRemsec

Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareEmbargo

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

T1068
Exploitation for Privilege Escalation
MalwareJHUHUGIT

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1068
Exploitation for Privilege Escalation
MalwarePandora

Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1068
Exploitation for Privilege Escalation
MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

T1068
Exploitation for Privilege Escalation
MalwareWingbird

Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.

T1068
Exploitation for Privilege Escalation
MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1068
Exploitation for Privilege Escalation
MalwareXCSSET

XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP.

T1068
Exploitation for Privilege Escalation
MalwareZox

Zox has the ability to leverage local and remote exploits to escalate privileges.

T1068
Exploitation for Privilege Escalation
ToolEmpire

Empire can exploit vulnerabilities such as MS16-032 and MS16-135.

T1068
Exploitation for Privilege Escalation
ToolPoshC2

PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099.

T1068
Exploitation for Privilege Escalation
MalwareZeroCleare

ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver.

T1069
Permission Groups Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell.

T1069
Permission Groups Discovery
GroupAPT3

APT3 has a tool that can enumerate the permissions associated with Windows groups.

T1069
Permission Groups Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.

T1069
Permission Groups Discovery
GroupAPT41

APT41 used net group commands to enumerate various Windows user groups and permissions.

T1069
Permission Groups Discovery
GroupScattered Spider

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

T1069
Permission Groups Discovery
GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1069
Permission Groups Discovery
GroupFIN13

FIN13 has enumerated all users and roles from a victim's main treasury system.

T1069
Permission Groups Discovery
MalwareTrickBot

TrickBot can identify the groups the user on a compromised host belongs to.

T1069
Permission Groups Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about groups.

T1069
Permission Groups Discovery
MalwareSiloscape

Siloscape checks for Kubernetes node permissions.

T1069
Permission Groups Discovery
MalwareIcedID

IcedID has the ability to identify Workgroup membership.

T1069
Permission Groups Discovery
MalwareCarbon

Carbon uses the net group command.

T1069
Permission Groups Discovery
ToolShimRatReporter

ShimRatReporter gathered the local privileges for the infected host.

T1069.001
Local Groups
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

T1069.001
Local Groups
CampaignC0015

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

T1069.001
Local Groups
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance.

T1069.001
Local Groups
CampaignOperation Wocao

During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group.

T1069.001
Local Groups
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: net localgroup administrator >> %temp%\download

T1069.001
Local Groups
GroupVolt Typhoon

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.

T1069.001
Local Groups
GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

T1069.001
Local Groups
GroupTurla

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.

T1069.001
Local Groups
GroupChimera

Chimera has used net localgroup administrators to identify accounts with local administrative rights.

T1069.001
Local Groups
GroupTonto Team

Tonto Team has used the ShowLocalGroupDetails command to identify administrator, user, and guest accounts on a compromised host.

T1069.001
Local Groups
GroupHEXANE

HEXANE has run `net localgroup` to enumerate local groups.

T1069.001
Local Groups
MalwarePOWRUNER

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.001
Local Groups
MalwareEmissary

Emissary has the capability to execute the command net localgroup administrators.

T1069.001
Local Groups
MalwareGomir

Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1069.001
Local Groups
MalwareKazuar

Kazuar gathers information about local groups and members.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.