Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1069.001 Local Groups |
MalwareFlagpro | Flagpro has been used to execute the |
| T1069.001 Local Groups |
MalwareExbyte | Exbyte checks whether the process is running with privileged local access during execution. |
| T1069.001 Local Groups |
MalwareEpic | Epic gathers information on local group names. |
| T1069.001 Local Groups |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of local groups of users from a system. |
| T1069.001 Local Groups |
MalwareSys10 | Sys10 collects the group name of the logged-in user and sends it to the C2. |
| T1069.001 Local Groups |
MalwareCobalt Strike | Cobalt Strike can use |
| T1069.001 Local Groups |
MalwareKwampirs | Kwampirs collects a list of users belonging to the local users and administrators groups with the commands |
| T1069.001 Local Groups |
MalwareJPIN | JPIN can obtain the permissions of the victim user. |
| T1069.001 Local Groups |
MalwareLunarWeb | LunarWeb can discover local group memberships. |
| T1069.001 Local Groups |
MalwareQakBot | QakBot can use |
| T1069.001 Local Groups |
MalwareHelminth | Helminth has checked the local administrators group. |
| T1069.001 Local Groups |
MalwareOSInfo | OSInfo has enumerated the local administrators group. |
| T1069.001 Local Groups |
ToolNet | Commands such as |
| T1069.001 Local Groups |
ToolBloodHound | BloodHound can collect information about local groups and members. |
| T1069.001 Local Groups |
ToolSILENTTRINITY | SILENTTRINITY can obtain a list of local groups and members. |
| T1069.001 Local Groups |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1069.002 Domain Groups |
CampaignC0015 | During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups. |
| T1069.002 Domain Groups |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups. |
| T1069.002 Domain Groups |
GroupVolt Typhoon | Volt Typhoon has run `net group` in compromised environments to discover domain groups. |
| T1069.002 Domain Groups |
GroupDragonfly | Dragonfly has used batch scripts to enumerate administrators and users in the domain. |
| T1069.002 Domain Groups |
GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| T1069.002 Domain Groups |
GroupMustang Panda | Mustang Panda has leveraged AdFind to enumerate domain groups. |
| T1069.002 Domain Groups |
GroupScattered Spider | Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser. |
| T1069.002 Domain Groups |
GroupOilRig | OilRig has used |
| T1069.002 Domain Groups |
GroupKe3chang | Ke3chang performs discovery of permission groups |
| T1069.002 Domain Groups |
GroupTurla | Turla has used |
| T1069.002 Domain Groups |
GroupMedusa Group | Medusa Group has utilized the `net group` command to query domain groups within the victim environment. |
| T1069.002 Domain Groups |
GroupToddyCat | ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines. |
| T1069.002 Domain Groups |
GroupINC Ransom | INC Ransom has enumerated domain groups on targeted hosts. |
| T1069.002 Domain Groups |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network. |
| T1069.002 Domain Groups |
GroupInception | Inception has used specific malware modules to gather domain membership. |
| T1069.002 Domain Groups |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information. |
| T1069.002 Domain Groups |
MalwarePOWRUNER | POWRUNER may collect domain group information by running |
| T1069.002 Domain Groups |
MalwareBADHATCH | BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators. |
| T1069.002 Domain Groups |
MalwareGootloader | Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable. |
| T1069.002 Domain Groups |
MalwareWellMess | WellMess can identify domain group membership for the current user. |
| T1069.002 Domain Groups |
MalwareBlackCat | BlackCat can determine if a user on a compromised host has domain admin privileges. |
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1069.002 Domain Groups |
MalwareCobalt Strike | Cobalt Strike can identify targets by querying account groups on a domain contoller. |
| T1069.002 Domain Groups |
MalwareREvil | REvil can identify the domain membership of a compromised host. |
| T1069.002 Domain Groups |
MalwareKwampirs | Kwampirs collects a list of domain groups with the command |
| T1069.002 Domain Groups |
MalwareLAMEHUG | |
| T1069.002 Domain Groups |
MalwareEgregor | Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind. |
| T1069.002 Domain Groups |
MalwareQilin | Qilin can run PowerShell cmdlets to discover domain groups. |
| T1069.002 Domain Groups |
MalwareSoreFang | SoreFang can enumerate domain groups by executing |
| T1069.002 Domain Groups |
MalwareHelminth | Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands |
| T1069.002 Domain Groups |
MalwareOSInfo | OSInfo specifically looks for Domain Admins and power users within the domain. |
| T1069.002 Domain Groups |
ToolNet | Commands such as |
| T1069.002 Domain Groups |
ToolBloodHound | BloodHound can collect information about domain groups and members. |
| T1069.002 Domain Groups |
ToolSILENTTRINITY | SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.