Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
MalwareZxShell | ZxShell has remote desktop functionality. |
| T1021.001 Remote Desktop Protocol |
MalwarenjRAT | njRAT has a module for performing remote desktop access. |
| T1021.001 Remote Desktop Protocol |
MalwarejRAT | jRAT can support RDP control. |
| T1021.001 Remote Desktop Protocol |
MalwareWarzoneRAT | WarzoneRAT has the ability to control an infected PC using RDP. |
| T1021.001 Remote Desktop Protocol |
ToolImminent Monitor | Imminent Monitor has a module for performing remote desktop access. |
| T1021.001 Remote Desktop Protocol |
ToolKoadic | Koadic can enable remote desktop on the victim's machine. |
| T1021.001 Remote Desktop Protocol |
ToolPupy | Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client. |
| T1021.001 Remote Desktop Protocol |
ToolQuasarRAT | QuasarRAT has a module for performing remote desktop access. |
| T1021.002 SMB/Windows Admin Shares |
MalwareStuxnet | Stuxnet propagates to available network shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwarereGeorg | reGeorg has the ability to tunnel SMB sessions. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRansomHub | RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2. |
| T1021.002 SMB/Windows Admin Shares |
MalwareEmotet | Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareOlympic Destroyer | Olympic Destroyer uses PsExec to interact with the |
| T1021.002 SMB/Windows Admin Shares |
MalwareRegin | The Regin malware platform can use Windows admin shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareConti | Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network. |
| T1021.002 SMB/Windows Admin Shares |
MalwareDiavol | Diavol can spread throughout a network via SMB prior to encryption. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLucifer | Lucifer can infect victims by brute forcing SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackEnergy | BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwarezwShell | zwShell has been copied over network shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNotPetya | NotPetya can use PsExec, which interacts with the |
| T1021.002 SMB/Windows Admin Shares |
MalwareConficker | Conficker variants spread through NetBIOS share propagation. |
| T1021.002 SMB/Windows Admin Shares |
MalwareAnchor | Anchor can support windows execution via SMB shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 3.0 | LockBit 3.0 can use SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRoyal | Royal can use SMB to connect to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareShamoon | Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware. |
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackByte Ransomware | BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRyuk | Ryuk has used the C$ network share for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to move laterally via SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareKwampirs | Kwampirs copies itself over network shares to move laterally on a victim network. |
| T1021.002 SMB/Windows Admin Shares |
MalwareQilin | Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1021.002 SMB/Windows Admin Shares |
MalwareZox | Zox has the ability to use SMB for communication. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNet Crawler | Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems. |
| T1021.002 SMB/Windows Admin Shares |
ToolNet | Lateral movement can be done with Net through |
| T1021.002 SMB/Windows Admin Shares |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
ToolPsExec | PsExec, a tool that has been used by adversaries, writes programs to the |
| T1021.002 SMB/Windows Admin Shares |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1021.003 Distributed Component Object Model |
MalwareCobalt Strike | Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution. |
| T1021.003 Distributed Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM. |
| T1021.003 Distributed Component Object Model |
ToolEmpire | Empire can utilize |
| T1021.004 SSH |
MalwarereGeorg | reGeorg can communicate using SSH through an HTTP tunnel. |
| T1021.004 SSH |
MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| T1021.004 SSH |
MalwareKinsing | Kinsing has used SSH for lateral movement. |
| T1021.004 SSH |
MalwareQilin | Qilin can enable SSH access on ESXi hosts. |
| T1021.004 SSH |
ToolEmpire | Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection. |
| T1021.005 VNC |
MalwareTrickBot | TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network |
| T1021.005 VNC |
MalwareLatrodectus | Latrodectus has routed C2 traffic using Keyhole VNC. |
| T1021.005 VNC |
MalwareDanBot | DanBot can use VNC for remote access to targeted systems. |
| T1021.005 VNC |
MalwareCarberp | Carberp can start a remote VNC session by downloading a new plugin. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.