ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1110.002
Password Cracking
GroupFIN6

FIN6 has extracted password hashes from ntds.dit to crack offline.

T1110.002
Password Cracking
MalwareNet Crawler

Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network.

T1110.003
Password Spraying
CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials.

T1110.003
Password Spraying
CampaignQuad7 Activity

Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds.

T1110.003
Password Spraying
GroupHAFNIUM

HAFNIUM has gained initial access through password spray attacks.

T1110.003
Password Spraying
GroupLeafminer

Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying.

T1110.003
Password Spraying
GroupAPT29

APT29 has conducted brute force password spray attacks.

T1110.003
Password Spraying
GroupChimera

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.

T1110.003
Password Spraying
GroupSilent Librarian

Silent Librarian has used collected lists of names and e-mail accounts to use in password spraying attacks against private sector targets.

T1110.003
Password Spraying
GroupEmber Bear

Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords.

T1110.003
Password Spraying
GroupAgrius

Agrius engaged in password spraying via SMB in victim environments.

T1110.003
Password Spraying
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

T1110.003
Password Spraying
GroupLazarus Group

Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords.

T1110.003
Password Spraying
GroupHEXANE

HEXANE has used password spraying attacks to obtain valid credentials.

T1110.003
Password Spraying
GroupAPT33

APT33 has used password spraying to gain access to target systems.

T1110.003
Password Spraying
MalwareLinux Rabbit

Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server.

T1110.003
Password Spraying
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.

T1110.003
Password Spraying
ToolMailSniper

MailSniper can be used for password spraying against Exchange and Office 365.

T1110.003
Password Spraying
ToolCrackMapExec

CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password.

T1110.004
Credential Stuffing
GroupChimera

Chimera has used credential stuffing against victim's remote services to obtain valid accounts.

T1110.004
Credential Stuffing
GroupVOID MANTICORE

VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments.

T1110.004
Credential Stuffing
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

T1111
Multi-Factor Authentication Interception
CampaignOperation Wocao

During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens.

T1111
Multi-Factor Authentication Interception
CampaignLeviathan Australian Intrusions

Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions.

T1111
Multi-Factor Authentication Interception
GroupKimsuky

Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication.

T1111
Multi-Factor Authentication Interception
GroupChimera

Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS.

T1111
Multi-Factor Authentication Interception
GroupAPT42

APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens.

T1111
Multi-Factor Authentication Interception
GroupLAPSUS$

LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval.

T1111
Multi-Factor Authentication Interception
MalwareSykipot

Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens.

T1111
Multi-Factor Authentication Interception
MalwareSLOWPULSE

SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure.

T1111
Multi-Factor Authentication Interception
Toolevilginx2

evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA.

T1112
Modify Registry
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications.

T1112
Modify Registry
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used batch files that modified registry keys.

T1112
Modify Registry
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. .

T1112
Modify Registry
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.

T1112
Modify Registry
CampaignOperation Wocao

During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled).

T1112
Modify Registry
GroupAPT38

APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys.

T1112
Modify Registry
GroupIndrik Spider

Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities.

T1112
Modify Registry
GroupBlackByte

BlackByte performed Registry modifications to escalate privileges and disable security tools.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1112
Modify Registry
GroupVolt Typhoon

Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).

T1112
Modify Registry
GroupPatchwork

A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs.

T1112
Modify Registry
GroupAPT41

APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.

T1112
Modify Registry
GroupDragonfly

Dragonfly has modified the Registry to perform multiple techniques through the use of Reg.

T1112
Modify Registry
GroupGorgon Group

Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under HKCU\Software\Microsoft\Office\.

T1112
Modify Registry
GroupAPT32

APT32's backdoor has modified the Windows Registry to store the backdoor's configuration.

T1112
Modify Registry
GroupGamaredon Group

Gamaredon Group has removed security settings for VBA macro execution by changing registry values HKCU\Software\Microsoft\Office\<version>\<product>\Security\VBAWarnings and HKCU\Software\Microsoft\Office\<version>\<product>\Security\AccessVBOM. Gamaredon Group has also modified Registry keys to hide folders and system files and to add the C2 address under `HKEY_CURRENT_USER\Console\WindowsUpdate`.

T1112
Modify Registry
GroupOilRig

OilRig has used reg.exe to modify system configuration.

T1112
Modify Registry
GroupAquatic Panda

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.

T1112
Modify Registry
GroupSaint Bear

Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.