Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1110.002 Password Cracking |
GroupFIN6 | FIN6 has extracted password hashes from ntds.dit to crack offline. |
| T1110.002 Password Cracking |
MalwareNet Crawler | Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network. |
| T1110.003 Password Spraying |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials. |
| T1110.003 Password Spraying |
CampaignQuad7 Activity | Quad7 Activity has conducted a throttled variant of password spraying techniques that only utilized a single attempt to sign in within a 24-hour time period, eluding brute force detection thresholds. |
| T1110.003 Password Spraying |
GroupHAFNIUM | HAFNIUM has gained initial access through password spray attacks. |
| T1110.003 Password Spraying |
GroupLeafminer | Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying. |
| T1110.003 Password Spraying |
GroupAPT29 | APT29 has conducted brute force password spray attacks. |
| T1110.003 Password Spraying |
GroupChimera | Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts. |
| T1110.003 Password Spraying |
GroupSilent Librarian | Silent Librarian has used collected lists of names and e-mail accounts to use in password spraying attacks against private sector targets. |
| T1110.003 Password Spraying |
GroupEmber Bear | Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords. |
| T1110.003 Password Spraying |
GroupAgrius | Agrius engaged in password spraying via SMB in victim environments. |
| T1110.003 Password Spraying |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks. |
| T1110.003 Password Spraying |
GroupLazarus Group | Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords. |
| T1110.003 Password Spraying |
GroupHEXANE | HEXANE has used password spraying attacks to obtain valid credentials. |
| T1110.003 Password Spraying |
GroupAPT33 | APT33 has used password spraying to gain access to target systems. |
| T1110.003 Password Spraying |
MalwareLinux Rabbit | Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server. |
| T1110.003 Password Spraying |
MalwareBad Rabbit | Bad Rabbit’s |
| T1110.003 Password Spraying |
ToolMailSniper | MailSniper can be used for password spraying against Exchange and Office 365. |
| T1110.003 Password Spraying |
ToolCrackMapExec | CrackMapExec can brute force credential authentication by using a supplied list of usernames and a single password. |
| T1110.004 Credential Stuffing |
GroupChimera | Chimera has used credential stuffing against victim's remote services to obtain valid accounts. |
| T1110.004 Credential Stuffing |
GroupVOID MANTICORE | VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments. |
| T1110.004 Credential Stuffing |
MalwareTrickBot | TrickBot uses brute-force attack against RDP with rdpscanDll module. |
| T1111 Multi-Factor Authentication Interception |
CampaignOperation Wocao | During Operation Wocao, threat actors used a custom collection method to intercept two-factor authentication soft tokens. |
| T1111 Multi-Factor Authentication Interception |
CampaignLeviathan Australian Intrusions | Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions. |
| T1111 Multi-Factor Authentication Interception |
GroupKimsuky | Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication. |
| T1111 Multi-Factor Authentication Interception |
GroupChimera | Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS. |
| T1111 Multi-Factor Authentication Interception |
GroupAPT42 | APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
| T1111 Multi-Factor Authentication Interception |
GroupLAPSUS$ | LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval. |
| T1111 Multi-Factor Authentication Interception |
MalwareSykipot | Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens. |
| T1111 Multi-Factor Authentication Interception |
MalwareSLOWPULSE | SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure. |
| T1111 Multi-Factor Authentication Interception |
Toolevilginx2 | evilginx2 can intercept authentication tokens to enable bypass of non-phishing resistant forms of MFA. |
| T1112 Modify Registry |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors, including Storm-2603, disabled security services via Registry modifications. |
| T1112 Modify Registry |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used batch files that modified registry keys. |
| T1112 Modify Registry |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching `rundll32.exe`, which in-turn launches the malware and communicates with C2 servers over the Internet. . |
| T1112 Modify Registry |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry. |
| T1112 Modify Registry |
CampaignOperation Wocao | During Operation Wocao, the threat actors enabled Wdigest by changing the `HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest` registry value from 0 (disabled) to 1 (enabled). |
| T1112 Modify Registry |
GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| T1112 Modify Registry |
GroupIndrik Spider | Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1112 Modify Registry |
GroupVolt Typhoon | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG). |
| T1112 Modify Registry |
GroupPatchwork | A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1112 Modify Registry |
GroupDragonfly | Dragonfly has modified the Registry to perform multiple techniques through the use of Reg. |
| T1112 Modify Registry |
GroupGorgon Group | Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under |
| T1112 Modify Registry |
GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| T1112 Modify Registry |
GroupGamaredon Group | Gamaredon Group has removed security settings for VBA macro execution by changing registry values |
| T1112 Modify Registry |
GroupOilRig | OilRig has used reg.exe to modify system configuration. |
| T1112 Modify Registry |
GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| T1112 Modify Registry |
GroupSaint Bear | Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.