Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1135 Network Share Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify network shares on compromised systems. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1135 Network Share Discovery |
MalwareRoyal | Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`. |
| T1135 Network Share Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions. |
| T1135 Network Share Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareBazar | Bazar can enumerate shared drives on the domain. |
| T1135 Network Share Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can discover remote shares. |
| T1135 Network Share Discovery |
MalwareZebrocy | Zebrocy identifies network drives when they are added to victim systems. |
| T1135 Network Share Discovery |
MalwareCobalt Strike | Cobalt Strike can query shared drives on the local system. |
| T1135 Network Share Discovery |
MalwareRamsay | Ramsay can scan for network drives which may contain documents for collection. |
| T1135 Network Share Discovery |
MalwareKwampirs | Kwampirs collects a list of network shares with the command |
| T1135 Network Share Discovery |
MalwareClop | Clop can enumerate network shares. |
| T1135 Network Share Discovery |
MalwareLunarWeb | LunarWeb can identify shared resources in compromised environments. |
| T1135 Network Share Discovery |
MalwareQilin | Qilin has the ability to list network drives. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1135 Network Share Discovery |
MalwareINC Ransomware | INC Ransomware has the ability to check for shared network drives to encrypt. |
| T1135 Network Share Discovery |
MalwareFIVEHANDS | FIVEHANDS can enumerate network shares and mounted drives on a network. |
| T1135 Network Share Discovery |
MalwareOSInfo | OSInfo discovers shares on the network |
| T1135 Network Share Discovery |
MalwareBitPaymer | BitPaymer can search for network shares on the domain or workgroup using |
| T1135 Network Share Discovery |
ToolNet | The |
| T1135 Network Share Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate shares on a compromised host. |
| T1135 Network Share Discovery |
ToolEmpire | Empire can find shared drives on the local system. |
| T1135 Network Share Discovery |
ToolCrackMapExec | CrackMapExec can enumerate the shared folders and associated permissions for a targeted network. |
| T1135 Network Share Discovery |
ToolKoadic | Koadic can scan local network for open SMB. |
| T1135 Network Share Discovery |
ToolPupy | Pupy can list local and remote shared drives and folders over SMB. |
| T1136 Create Account |
MalwareLockBit 2.0 | LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| T1136.001 Local Account |
MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| T1136.001 Local Account |
MalwareS-Type | S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareDarkGate | DarkGate creates a local user account, |
| T1136.001 Local Account |
MalwareCarbanak | Carbanak can create a Windows account. |
| T1136.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has created user accounts. |
| T1136.001 Local Account |
MalwareServHelper | ServHelper has created a new user named "supportaccount". |
| T1136.001 Local Account |
MalwareCalisto | Calisto has the capability to add its own account to the victim's machine. |
| T1136.001 Local Account |
MalwareGoldenSpy | GoldenSpy can create new users on an infected system. |
| T1136.001 Local Account |
MalwareZxShell | ZxShell has a feature to create local user accounts. |
| T1136.001 Local Account |
MalwareMis-Type | Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`. |
| T1136.001 Local Account |
MalwareHiddenWasp | HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine. |
| T1136.001 Local Account |
ToolNet | The |
| T1136.001 Local Account |
ToolEmpire | Empire has a module for creating a local user if permissions allow. |
| T1136.001 Local Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create local system accounts. |
| T1136.001 Local Account |
MalwareFlame | Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
| T1136.002 Domain Account |
ToolNet | The |
| T1136.002 Domain Account |
ToolEmpire | Empire has a module for creating a new domain user if permissions allow. |
| T1136.002 Domain Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create domain accounts. |
| T1136.002 Domain Account |
ToolPsExec | PsExec has the ability to remotely create accounts on target systems. |
| T1136.003 Cloud Account |
ToolAADInternals | AADInternals can create new Azure AD users. |
| T1137.001 Office Template Macros |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro. |
| T1137.001 Office Template Macros |
MalwareCobalt Strike | Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission. |
| T1137.001 Office Template Macros |
MalwareBackConfig | BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros. |
| T1137.003 Outlook Forms |
ToolRuler | Ruler can be used to automate the abuse of Outlook Forms to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.