ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1095
Non-Application Layer Protocol
MalwarePHOREAL

PHOREAL communicates via ICMP for C2.

T1095
Non-Application Layer Protocol
MalwareLizar

Lizar has used a raw TCP connection to communicate with the C2 server.

T1095
Non-Application Layer Protocol
MalwareHiddenWasp

HiddenWasp communicates with a simple network protocol over TCP.

T1095
Non-Application Layer Protocol
MalwareWarzoneRAT

WarzoneRAT can communicate with its C2 server via TCP over port 5200.

T1095
Non-Application Layer Protocol
ToolFRP

FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP.

T1095
Non-Application Layer Protocol
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use TCP for external C2.

T1095
Non-Application Layer Protocol
ToolMythic

Mythic supports WebSocket and TCP-based C2 profiles.

T1095
Non-Application Layer Protocol
ToolQuasarRAT

QuasarRAT can use TCP for C2 communication.

T1098
Account Manipulation
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network.

T1098
Account Manipulation
GroupHAFNIUM

HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts.

T1098
Account Manipulation
GroupScattered Spider

Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere.

T1098
Account Manipulation
GroupLazarus Group

Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account.

T1098
Account Manipulation
GroupVOID MANTICORE

VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access.

T1098
Account Manipulation
MalwareCalisto

Calisto adds permissions and remote logins to all users.

T1098
Account Manipulation
MalwareShai-Hulud

Shai-Hulud has modified GitHub account settings for private repositories and changed them to public.

T1098
Account Manipulation
ToolMimikatz

The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The LSADUMP::ChangeNTLM and LSADUMP::SetNTLM modules can also manipulate the password hash of an account without knowing the clear text value.

T1098
Account Manipulation
GroupTeamPCP

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.

T1098.001
Additional Cloud Credentials
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals.

T1098.001
Additional Cloud Credentials
CampaignC0027

During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA.

T1098.001
Additional Cloud Credentials
GroupStorm-0501

Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method.

T1098.001
Additional Cloud Credentials
ToolPacu

Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users.

T1098.002
Additional Email Delegate Permissions
CampaignHomeLand Justice

During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes.

T1098.002
Additional Email Delegate Permissions
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals.

T1098.002
Additional Email Delegate Permissions
GroupAPT29

APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails.

T1098.002
Additional Email Delegate Permissions
GroupAPT28

APT28 has used a Powershell cmdlet to grant the ApplicationImpersonation role to a compromised account.

T1098.002
Additional Email Delegate Permissions
GroupMagic Hound

Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations.

T1098.003
Additional Cloud Roles
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle.

T1098.003
Additional Cloud Roles
CampaignC0027

During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges.

T1098.003
Additional Cloud Roles
GroupScattered Spider

Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure.

T1098.003
Additional Cloud Roles
GroupStorm-0501

Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions.

T1098.003
Additional Cloud Roles
GroupLAPSUS$

LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances.

T1098.004
SSH Authorized Keys
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution.

T1098.004
SSH Authorized Keys
GroupSalt Typhoon

Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices.

T1098.004
SSH Authorized Keys
GroupTeamTNT

TeamTNT has added RSA keys in authorized_keys.

T1098.004
SSH Authorized Keys
GroupEarth Lusca

Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH.

T1098.004
SSH Authorized Keys
MalwareSkidmap

Skidmap has the ability to add the public key of its handlers to the authorized_keys file to maintain persistence on an infected host.

T1098.004
SSH Authorized Keys
MalwareBundlore

Bundlore creates a new key pair with ssh-keygen and drops the newly created user key in authorized_keys to enable remote login.

T1098.004
SSH Authorized Keys
MalwareXCSSET

XCSSET will create an ssh key if necessary with the ssh-keygen -t rsa -f $HOME/.ssh/id_rsa -P command. XCSSET will upload a private key file to the server to remotely access the host without a password.

T1098.005
Device Registration
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command.

T1098.005
Device Registration
CampaignC0027

During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN.

T1098.005
Device Registration
GroupAPT29

APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account.

T1098.005
Device Registration
ToolAADInternals

AADInternals can register a device to Azure AD.

T1098.007
Additional Local or Domain Groups
GroupAPT3

APT3 has been known to add created accounts to local admin groups to maintain elevated access.

T1098.007
Additional Local or Domain Groups
GroupKimsuky

Kimsuky has added accounts to specific groups with net localgroup.

T1098.007
Additional Local or Domain Groups
GroupAPT41

APT41 has added user accounts to the User and Admin groups.

T1098.007
Additional Local or Domain Groups
GroupDragonfly

Dragonfly has added newly created accounts to the administrators group to maintain elevated access.

T1098.007
Additional Local or Domain Groups
GroupAPT5

APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation.

T1098.007
Additional Local or Domain Groups
GroupMagic Hound

Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups.

T1098.007
Additional Local or Domain Groups
GroupFIN13

FIN13 has assigned newly created accounts the sysadmin role to maintain persistence.

T1098.007
Additional Local or Domain Groups
MalwareDarkGate

DarkGate elevates accounts created through the malware to the local administration group during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.