Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1095 Non-Application Layer Protocol |
MalwarePHOREAL | PHOREAL communicates via ICMP for C2. |
| T1095 Non-Application Layer Protocol |
MalwareLizar | Lizar has used a raw TCP connection to communicate with the C2 server. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenWasp | HiddenWasp communicates with a simple network protocol over TCP. |
| T1095 Non-Application Layer Protocol |
MalwareWarzoneRAT | WarzoneRAT can communicate with its C2 server via TCP over port 5200. |
| T1095 Non-Application Layer Protocol |
ToolFRP | FRP can communicate over TCP, TCP stream multiplexing, KERN Communications Protocol (KCP), QUIC, and UDP. |
| T1095 Non-Application Layer Protocol |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use TCP for external C2. |
| T1095 Non-Application Layer Protocol |
ToolMythic | Mythic supports WebSocket and TCP-based C2 profiles. |
| T1095 Non-Application Layer Protocol |
ToolQuasarRAT | QuasarRAT can use TCP for C2 communication. |
| T1098 Account Manipulation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the `sp_addlinkedsrvlogin` command in MS-SQL to create a link between a created account and other servers in the network. |
| T1098 Account Manipulation |
GroupHAFNIUM | HAFNIUM has granted privileges to domain accounts and reset the password for default admin accounts. |
| T1098 Account Manipulation |
GroupScattered Spider | Scattered Spider has added accounts to the ESX Admins group to grant them full admin rights in vSphere. |
| T1098 Account Manipulation |
GroupLazarus Group | Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account. |
| T1098 Account Manipulation |
GroupVOID MANTICORE | VOID MANTICORE has leveraged access to administrative control systems to achieve disruptive effects, consistent with administrative account abuse or privilege escalation within existing access. |
| T1098 Account Manipulation |
MalwareCalisto | Calisto adds permissions and remote logins to all users. |
| T1098 Account Manipulation |
MalwareShai-Hulud | Shai-Hulud has modified GitHub account settings for private repositories and changed them to public. |
| T1098 Account Manipulation |
ToolMimikatz | The Mimikatz credential dumper has been extended to include Skeleton Key domain controller authentication bypass functionality. The |
| T1098 Account Manipulation |
GroupTeamPCP | TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public. |
| T1098.001 Additional Cloud Credentials |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals. |
| T1098.001 Additional Cloud Credentials |
CampaignC0027 | During C0027, Scattered Spider used aws_consoler to create temporary federated credentials for fake users in order to obfuscate which AWS credential is compromised and enable pivoting from the AWS CLI to console sessions without MFA. |
| T1098.001 Additional Cloud Credentials |
GroupStorm-0501 | Storm-0501 has reset the password of identified administrator accounts that lack MFA and registered their own MFA method. |
| T1098.001 Additional Cloud Credentials |
ToolPacu | Pacu can generate SSH and API keys for AWS infrastructure and additional API keys for other IAM users. |
| T1098.002 Additional Email Delegate Permissions |
CampaignHomeLand Justice | During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes. |
| T1098.002 Additional Email Delegate Permissions |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT29 | APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT28 | APT28 has used a Powershell cmdlet to grant the |
| T1098.002 Additional Email Delegate Permissions |
GroupMagic Hound | Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations. |
| T1098.003 Additional Cloud Roles |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 granted `company administrator` privileges to a newly created service principle. |
| T1098.003 Additional Cloud Roles |
CampaignC0027 | During C0027, Scattered Spider used IAM manipulation to gain persistence and to assume or elevate privileges. |
| T1098.003 Additional Cloud Roles |
GroupScattered Spider | Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure. |
| T1098.003 Additional Cloud Roles |
GroupStorm-0501 | Storm-0501 has elevated their access to Azure resources using `Microsoft.Authorization/elevateAccess/action` and `Microsoft.Authorization/roleAssignments/write` operations to gain User Access Administrator and Owner Azure roles over the victims’ Azure subscriptions. |
| T1098.003 Additional Cloud Roles |
GroupLAPSUS$ | LAPSUS$ has added the global admin role to accounts they have created in the targeted organization's cloud instances. |
| T1098.004 SSH Authorized Keys |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used SSH access enabled by authorized_keys files for remote execution. |
| T1098.004 SSH Authorized Keys |
GroupSalt Typhoon | Salt Typhoon has added SSH authorized_keys under root or other users at the Linux level on compromised network devices. |
| T1098.004 SSH Authorized Keys |
GroupTeamTNT | TeamTNT has added RSA keys in |
| T1098.004 SSH Authorized Keys |
GroupEarth Lusca | Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH. |
| T1098.004 SSH Authorized Keys |
MalwareSkidmap | Skidmap has the ability to add the public key of its handlers to the |
| T1098.004 SSH Authorized Keys |
MalwareBundlore | Bundlore creates a new key pair with |
| T1098.004 SSH Authorized Keys |
MalwareXCSSET | XCSSET will create an ssh key if necessary with the |
| T1098.005 Device Registration |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 registered devices in order to enable mailbox syncing via the `Set-CASMailbox` command. |
| T1098.005 Device Registration |
CampaignC0027 | During C0027, Scattered Spider registered devices for MFA to maintain persistence through victims' VPN. |
| T1098.005 Device Registration |
GroupAPT29 | APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account. |
| T1098.005 Device Registration |
ToolAADInternals | AADInternals can register a device to Azure AD. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT3 | APT3 has been known to add created accounts to local admin groups to maintain elevated access. |
| T1098.007 Additional Local or Domain Groups |
GroupKimsuky | Kimsuky has added accounts to specific groups with |
| T1098.007 Additional Local or Domain Groups |
GroupAPT41 | APT41 has added user accounts to the User and Admin groups. |
| T1098.007 Additional Local or Domain Groups |
GroupDragonfly | Dragonfly has added newly created accounts to the administrators group to maintain elevated access. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT5 | APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation. |
| T1098.007 Additional Local or Domain Groups |
GroupMagic Hound | Magic Hound has added a user named DefaultAccount to the Administrators and Remote Desktop Users groups. |
| T1098.007 Additional Local or Domain Groups |
GroupFIN13 | FIN13 has assigned newly created accounts the sysadmin role to maintain persistence. |
| T1098.007 Additional Local or Domain Groups |
MalwareDarkGate | DarkGate elevates accounts created through the malware to the local administration group during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.