ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
MalwareZxShell

ZxShell has remote desktop functionality.

T1021.001
Remote Desktop Protocol
MalwarenjRAT

njRAT has a module for performing remote desktop access.

T1021.001
Remote Desktop Protocol
MalwarejRAT

jRAT can support RDP control.

T1021.001
Remote Desktop Protocol
MalwareWarzoneRAT

WarzoneRAT has the ability to control an infected PC using RDP.

T1021.001
Remote Desktop Protocol
ToolImminent Monitor

Imminent Monitor has a module for performing remote desktop access.

T1021.001
Remote Desktop Protocol
ToolKoadic

Koadic can enable remote desktop on the victim's machine.

T1021.001
Remote Desktop Protocol
ToolPupy

Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client.

T1021.001
Remote Desktop Protocol
ToolQuasarRAT

QuasarRAT has a module for performing remote desktop access.

T1021.002
SMB/Windows Admin Shares
MalwareStuxnet

Stuxnet propagates to available network shares.

T1021.002
SMB/Windows Admin Shares
MalwarereGeorg

reGeorg has the ability to tunnel SMB sessions.

T1021.002
SMB/Windows Admin Shares
MalwareRansomHub

RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2.

T1021.002
SMB/Windows Admin Shares
MalwareEmotet

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareOlympic Destroyer

Olympic Destroyer uses PsExec to interact with the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareRegin

The Regin malware platform can use Windows admin shares to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareConti

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

T1021.002
SMB/Windows Admin Shares
MalwareDiavol

Diavol can spread throughout a network via SMB prior to encryption.

T1021.002
SMB/Windows Admin Shares
MalwareLucifer

Lucifer can infect victims by brute forcing SMB.

T1021.002
SMB/Windows Admin Shares
MalwareBlackEnergy

BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares.

T1021.002
SMB/Windows Admin Shares
MalwarezwShell

zwShell has been copied over network shares to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareNotPetya

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareConficker

Conficker variants spread through NetBIOS share propagation.

T1021.002
SMB/Windows Admin Shares
MalwareAnchor

Anchor can support windows execution via SMB shares.

T1021.002
SMB/Windows Admin Shares
MalwareLockBit 3.0

LockBit 3.0 can use SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareRoyal

Royal can use SMB to connect to move laterally.

T1021.002
SMB/Windows Admin Shares
MalwareShamoon

Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware.

T1021.002
SMB/Windows Admin Shares
MalwareBlackByte Ransomware

BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB.

T1021.002
SMB/Windows Admin Shares
MalwareRyuk

Ryuk has used the C$ network share for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareLockBit 2.0

LockBit 2.0 has the ability to move laterally via SMB.

T1021.002
SMB/Windows Admin Shares
MalwareCobalt Strike

Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareKwampirs

Kwampirs copies itself over network shares to move laterally on a victim network.

T1021.002
SMB/Windows Admin Shares
MalwareQilin

Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename.

T1021.002
SMB/Windows Admin Shares
MalwareZox

Zox has the ability to use SMB for communication.

T1021.002
SMB/Windows Admin Shares
MalwareNet Crawler

Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems.

T1021.002
SMB/Windows Admin Shares
ToolNet

Lateral movement can be done with Net through net use commands to connect to the on remote systems.

T1021.002
SMB/Windows Admin Shares
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.

T1021.002
SMB/Windows Admin Shares
ToolPsExec

PsExec, a tool that has been used by adversaries, writes programs to the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareDuqu

Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware.

T1021.003
Distributed Component Object Model
MalwareCobalt Strike

Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution.

T1021.003
Distributed Component Object Model
ToolSILENTTRINITY

SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM.

T1021.003
Distributed Component Object Model
ToolEmpire

Empire can utilize Invoke-DCOM to leverage remote COM execution for lateral movement.

T1021.004
SSH
MalwarereGeorg

reGeorg can communicate using SSH through an HTTP tunnel.

T1021.004
SSH
MalwareCobalt Strike

Cobalt Strike can SSH to a remote service.

T1021.004
SSH
MalwareKinsing

Kinsing has used SSH for lateral movement.

T1021.004
SSH
MalwareQilin

Qilin can enable SSH access on ESXi hosts.

T1021.004
SSH
ToolEmpire

Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection.

T1021.005
VNC
MalwareTrickBot

TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network

T1021.005
VNC
MalwareLatrodectus

Latrodectus has routed C2 traffic using Keyhole VNC.

T1021.005
VNC
MalwareDanBot

DanBot can use VNC for remote access to targeted systems.

T1021.005
VNC
MalwareCarberp

Carberp can start a remote VNC session by downloading a new plugin.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.