ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1069.001
Local Groups
MalwareFlagpro

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

T1069.001
Local Groups
MalwareExbyte

Exbyte checks whether the process is running with privileged local access during execution.

T1069.001
Local Groups
MalwareEpic

Epic gathers information on local group names.

T1069.001
Local Groups
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of local groups of users from a system.

T1069.001
Local Groups
MalwareSys10

Sys10 collects the group name of the logged-in user and sends it to the C2.

T1069.001
Local Groups
MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

T1069.001
Local Groups
MalwareKwampirs

Kwampirs collects a list of users belonging to the local users and administrators groups with the commands net localgroup administrators and net localgroup users.

T1069.001
Local Groups
MalwareJPIN

JPIN can obtain the permissions of the victim user.

T1069.001
Local Groups
MalwareLunarWeb

LunarWeb can discover local group memberships.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1069.001
Local Groups
MalwareHelminth

Helminth has checked the local administrators group.

T1069.001
Local Groups
MalwareOSInfo

OSInfo has enumerated the local administrators group.

T1069.001
Local Groups
ToolNet

Commands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.

T1069.001
Local Groups
ToolBloodHound

BloodHound can collect information about local groups and members.

T1069.001
Local Groups
ToolSILENTTRINITY

SILENTTRINITY can obtain a list of local groups and members.

T1069.001
Local Groups
ToolPoshC2

PoshC2 contains modules, such as Get-LocAdm for enumerating permission groups.

T1069.002
Domain Groups
CampaignC0015

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.

T1069.002
Domain Groups
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used AdFind to enumerate domain groups.

T1069.002
Domain Groups
GroupVolt Typhoon

Volt Typhoon has run `net group` in compromised environments to discover domain groups.

T1069.002
Domain Groups
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1069.002
Domain Groups
GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1069.002
Domain Groups
GroupOilRig

OilRig has used net group /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to find domain group permission settings.

T1069.002
Domain Groups
GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

T1069.002
Domain Groups
GroupTurla

Turla has used net group "Domain Admins" /domain to identify domain administrators.

T1069.002
Domain Groups
GroupMedusa Group

Medusa Group has utilized the `net group` command to query domain groups within the victim environment.

T1069.002
Domain Groups
GroupToddyCat

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1069.002
Domain Groups
GroupINC Ransom

INC Ransom has enumerated domain groups on targeted hosts.

T1069.002
Domain Groups
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.

T1069.002
Domain Groups
GroupInception

Inception has used specific malware modules to gather domain membership.

T1069.002
Domain Groups
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.

T1069.002
Domain Groups
MalwarePOWRUNER

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1069.002
Domain Groups
MalwareBADHATCH

BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators.

T1069.002
Domain Groups
MalwareGootloader

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1069.002
Domain Groups
MalwareWellMess

WellMess can identify domain group membership for the current user.

T1069.002
Domain Groups
MalwareBlackCat

BlackCat can determine if a user on a compromised host has domain admin privileges.

T1069.002
Domain Groups
MalwareLatrodectus

Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`.

T1069.002
Domain Groups
MalwareCobalt Strike

Cobalt Strike can identify targets by querying account groups on a domain contoller.

T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1069.002
Domain Groups
MalwareKwampirs

Kwampirs collects a list of domain groups with the command net localgroup /domain.

T1069.002
Domain Groups
MalwareLAMEHUG

LAMEHUG can use dsquery to gather domain group information.

T1069.002
Domain Groups
MalwareEgregor

Egregor can conduct Active Directory reconnaissance using tools such as Sharphound or AdFind.

T1069.002
Domain Groups
MalwareQilin

Qilin can run PowerShell cmdlets to discover domain groups.

T1069.002
Domain Groups
MalwareSoreFang

SoreFang can enumerate domain groups by executing net.exe group /domain.

T1069.002
Domain Groups
MalwareHelminth

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1069.002
Domain Groups
MalwareOSInfo

OSInfo specifically looks for Domain Admins and power users within the domain.

T1069.002
Domain Groups
ToolNet

Commands such as net group /domain can be used in Net to gather information about and manipulate groups.

T1069.002
Domain Groups
ToolBloodHound

BloodHound can collect information about domain groups and members.

T1069.002
Domain Groups
ToolSILENTTRINITY

SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.