ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1135
Network Share Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify network shares on compromised systems.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1135
Network Share Discovery
MalwareRoyal

Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.

T1135
Network Share Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.

T1135
Network Share Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareBazar

Bazar can enumerate shared drives on the domain.

T1135
Network Share Discovery
MalwareLockBit 2.0

LockBit 2.0 can discover remote shares.

T1135
Network Share Discovery
MalwareZebrocy

Zebrocy identifies network drives when they are added to victim systems.

T1135
Network Share Discovery
MalwareCobalt Strike

Cobalt Strike can query shared drives on the local system.

T1135
Network Share Discovery
MalwareRamsay

Ramsay can scan for network drives which may contain documents for collection.

T1135
Network Share Discovery
MalwareKwampirs

Kwampirs collects a list of network shares with the command net share.

T1135
Network Share Discovery
MalwareClop

Clop can enumerate network shares.

T1135
Network Share Discovery
MalwareLunarWeb

LunarWeb can identify shared resources in compromised environments.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1135
Network Share Discovery
MalwareINC Ransomware

INC Ransomware has the ability to check for shared network drives to encrypt.

T1135
Network Share Discovery
MalwareFIVEHANDS

FIVEHANDS can enumerate network shares and mounted drives on a network.

T1135
Network Share Discovery
MalwareOSInfo

OSInfo discovers shares on the network

T1135
Network Share Discovery
MalwareBitPaymer

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

T1135
Network Share Discovery
ToolNet

The net view \\remotesystem and net share commands in Net can be used to find shared drives and directories on remote and local systems respectively.

T1135
Network Share Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate shares on a compromised host.

T1135
Network Share Discovery
ToolEmpire

Empire can find shared drives on the local system.

T1135
Network Share Discovery
ToolCrackMapExec

CrackMapExec can enumerate the shared folders and associated permissions for a targeted network.

T1135
Network Share Discovery
ToolKoadic

Koadic can scan local network for open SMB.

T1135
Network Share Discovery
ToolPupy

Pupy can list local and remote shared drives and folders over SMB.

T1136
Create Account
MalwareLockBit 2.0

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

T1136.001
Local Account
MalwareHildegard

Hildegard has created a user named “monerodaemon”.

T1136.001
Local Account
MalwareS-Type

S-Type may create a temporary user on the system named `Lost_{Unique Identifier}` with the password `pond~!@6”{Unique Identifier}`.

T1136.001
Local Account
MalwareDarkGate

DarkGate creates a local user account, SafeMode, via net user commands.

T1136.001
Local Account
MalwareCarbanak

Carbanak can create a Windows account.

T1136.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has created user accounts.

T1136.001
Local Account
MalwareServHelper

ServHelper has created a new user named "supportaccount".

T1136.001
Local Account
MalwareCalisto

Calisto has the capability to add its own account to the victim's machine.

T1136.001
Local Account
MalwareGoldenSpy

GoldenSpy can create new users on an infected system.

T1136.001
Local Account
MalwareZxShell

ZxShell has a feature to create local user accounts.

T1136.001
Local Account
MalwareMis-Type

Mis-Type may create a temporary user on the system named `Lost_{Unique Identifier}`.

T1136.001
Local Account
MalwareHiddenWasp

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

T1136.001
Local Account
ToolNet

The net user username \password commands in Net can be used to create a local account.

T1136.001
Local Account
ToolEmpire

Empire has a module for creating a local user if permissions allow.

T1136.001
Local Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create local system accounts.

T1136.001
Local Account
MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

T1136.002
Domain Account
ToolNet

The net user username \password \domain commands in Net can be used to create a domain account.

T1136.002
Domain Account
ToolEmpire

Empire has a module for creating a new domain user if permissions allow.

T1136.002
Domain Account
ToolPupy

Pupy can user PowerView to execute “net user” commands and create domain accounts.

T1136.002
Domain Account
ToolPsExec

PsExec has the ability to remotely create accounts on target systems.

T1136.003
Cloud Account
ToolAADInternals

AADInternals can create new Azure AD users.

T1137.001
Office Template Macros
MalwareROAMINGHOUSE

ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro.

T1137.001
Office Template Macros
MalwareCobalt Strike

Cobalt Strike has the ability to use an Excel Workbook to execute additional code by enabling Office to trust macros and execute code without user permission.

T1137.001
Office Template Macros
MalwareBackConfig

BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros.

T1137.003
Outlook Forms
ToolRuler

Ruler can be used to automate the abuse of Outlook Forms to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.