ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1210
Exploitation of Remote Services
MalwareLucifer

Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144).

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1210
Exploitation of Remote Services
MalwareConficker

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

T1210
Exploitation of Remote Services
MalwareWannaCry

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1210
Exploitation of Remote Services
MalwareQakBot

QakBot can move laterally using worm-like functionality through exploitation of SMB.

T1210
Exploitation of Remote Services
ToolEmpire

Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers.

T1210
Exploitation of Remote Services
ToolPoshC2

PoshC2 contains a module for exploiting SMB via EternalBlue.

T1210
Exploitation of Remote Services
MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

T1213
Data from Information Repositories
MalwareRaccoon Stealer

Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service.

T1213
Data from Information Repositories
MalwareTroll Stealer

Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems.

T1213.001
Confluence
ToolTruffleHog

TruffleHog has collected credentials and data associated with Confluence.

T1213.002
Sharepoint
Toolspwebmember

spwebmember is used to enumerate and dump information from Microsoft SharePoint.

T1213.002
Sharepoint
ToolTruffleHog

TruffleHog has searched SharePoint for data and credentials.

T1213.003
Code Repositories
MalwareGlassWorm

GlassWorm has gathered code repository authentication materials for NPM and GitHub. GlassWorm has collected details pertaining to the npm configuration data for `_authToken`.

T1213.003
Code Repositories
MalwareShai-Hulud

Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them.

T1213.003
Code Repositories
ToolTruffleHog

TruffleHog has gathered data and credentials from code repositories.

T1213.003
Code Repositories
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target sensitive file paths in Git repos to extract credentials.

T1213.003
Code Repositories
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories.

T1213.005
Messaging Applications
ToolTruffleHog

TruffleHog has obtained data and credentials associated with messaging applications to include Slack.

T1213.006
Databases
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list and extract data from SQL databases.

T1213.006
Databases
MalwareGlassWorm

GlassWorm has collected data from macOS devices through the gathering of Apple Notes related files by targeting `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite`, `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-wal`, and `/Library/Group Containers/group.com.apple.notes/NoteStore.sqlite-shm`.

T1213.006
Databases
MalwareMgBot

MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices.

T1213.006
Databases
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can extract credentials from multiple database configuration files including ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, and /etc/mysql/my.cnf.

T1217
Browser Information Discovery
MalwareMachete

Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers.

T1217
Browser Information Discovery
MalwarePowerLess

PowerLess has a browser info stealer module that can read Chrome and Edge browser database files.

T1217
Browser Information Discovery
MalwareMafalda

Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file.

T1217
Browser Information Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.

T1217
Browser Information Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server victim browser bookmarks.

T1217
Browser Information Discovery
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1217
Browser Information Discovery
MalwareLightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.

T1217
Browser Information Discovery
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareDarkWatchman

DarkWatchman can retrieve browser history.

T1217
Browser Information Discovery
MalwareLumma Stealer

Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers.

T1217
Browser Information Discovery
MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

T1217
Browser Information Discovery
MalwareRedLine Stealer

RedLine Stealer can collect information from browsers and browser extensions.

T1217
Browser Information Discovery
MalwareSUGARDUMP

SUGARDUMP has collected browser bookmark and history information.

T1217
Browser Information Discovery
MalwareCalisto

Calisto collects information on bookmarks from Google Chrome.

T1217
Browser Information Discovery
MalwareTroll Stealer

Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions.

T1217
Browser Information Discovery
MalwareLizar

Lizar can retrieve browser history and database files.

T1217
Browser Information Discovery
MalwareDtrack

Dtrack can retrieve browser history.

T1217
Browser Information Discovery
ToolEmpire

Empire has the ability to gather browser data such as bookmarks and visited sites.

T1218.001
Compiled HTML File
MalwareAstaroth

Astaroth uses ActiveX objects for file execution and manipulation.

T1218.002
Control Panel
MalwareInvisiMole

InvisiMole can register itself for execution and persistence via the Control Panel.

T1218.002
Control Panel
MalwareReaver

Reaver drops and executes a malicious CPL file as its payload.

T1218.003
CMSTP
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile.

T1218.003
CMSTP
MalwareLockBit 3.0

LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges.

T1218.004
InstallUtil
MalwareWhisperGate

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.

T1218.004
InstallUtil
MalwareSaint Bot

Saint Bot had used `InstallUtil.exe` to download and deploy executables.

T1218.004
InstallUtil
MalwareChaes

Chaes has used Installutill to download content.

T1218.004
InstallUtil
ToolCovenant

Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.