ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1548.003
Sudo and Sudo Caching
MalwareCobalt Strike

Cobalt Strike can use sudo to run a command.

T1548.003
Sudo and Sudo Caching
MalwareProton

Proton modifies the tty_tickets line in the sudoers file.

T1548.003
Sudo and Sudo Caching
MalwareShai-Hulud

Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`.

T1548.003
Sudo and Sudo Caching
MalwareDok

Dok adds admin ALL=(ALL) NOPASSWD: ALL to the /etc/sudoers file.

T1548.003
Sudo and Sudo Caching
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `sudo` for code execution.

T1548.003
Sudo and Sudo Caching
MalwareCanisterWorm

CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command.

T1548.004
Elevated Execution with Prompt
MalwareOSX/Shlayer

OSX/Shlayer can escalate privileges to root by asking the user for credentials.

T1548.006
TCC Manipulation
MalwareXCSSET

For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access.

T1550
Use Alternate Authentication Material
MalwareFoggyWeb

FoggyWeb can allow abuse of a compromised AD FS server's SAML token.

T1550.001
Application Access Token
MalwareCreepyDrive

CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive.

T1550.001
Application Access Token
MalwareShai-Hulud

Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts.

T1550.001
Application Access Token
ToolPeirates

Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts.

T1550.001
Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to authenticate using stolen application access tokens.

T1550.001
Application Access Token
MalwareCanisterWorm

CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope.

T1550.001
Application Access Token
MalwareKali365

Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules.

T1550.002
Pass the Hash
MalwareBADHATCH

BADHATCH can perform pass the hash on compromised machines with x64 versions.

T1550.002
Pass the Hash
MalwareHOPLIGHT

HOPLIGHT has been observed loading several APIs associated with Pass the Hash.

T1550.002
Pass the Hash
MalwareCobalt Strike

Cobalt Strike can perform pass the hash.

T1550.002
Pass the Hash
ToolEmpire

Empire can perform pass the hash attacks.

T1550.002
Pass the Hash
ToolPoshC2

PoshC2 has a number of modules that leverage pass the hash for lateral movement.

T1550.002
Pass the Hash
ToolPass-The-Hash Toolkit

Pass-The-Hash Toolkit can perform pass the hash.

T1550.002
Pass the Hash
ToolMimikatz

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

T1550.002
Pass the Hash
ToolCrackMapExec

CrackMapExec can pass the hash to authenticate via SMB.

T1550.003
Pass the Ticket
MalwareSeaDuke

Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication.

T1550.003
Pass the Ticket
ToolMimikatz

Mimikatz’s LSADUMP::DCSync and KERBEROS::PTT modules implement the three steps required to extract the krbtgt account hash and create/use Kerberos tickets.

T1550.003
Pass the Ticket
ToolPupy

Pupy can also perform pass-the-ticket.

T1552
Unsecured Credentials
MalwareDarkGate

DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe.

T1552
Unsecured Credentials
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1552
Unsecured Credentials
ToolNPPSPY

NPPSPY captures credentials by recording them through an alternative network listener registered to the mpnotify.exe process, allowing for cleartext recording of logon information.

T1552
Unsecured Credentials
ToolPacu

Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates.

T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1552.001
Credentials In Files
MalwareSmoke Loader

Smoke Loader searches for files named logins.json to parse for credentials.

T1552.001
Credentials In Files
MalwareEmotet

Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user.

T1552.001
Credentials In Files
MalwareHildegard

Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens.

T1552.001
Credentials In Files
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.

T1552.001
Credentials In Files
MalwareXTunnel

XTunnel is capable of accessing locally stored passwords on victims.

T1552.001
Credentials In Files
Malwarepngdowner

If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.001
Credentials In Files
MalwarePysa

Pysa has extracted credentials from the password database before encrypting the files.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1552.001
Credentials In Files
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from configuration or support files.

T1552.001
Credentials In Files
MalwarejRAT

jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk.

T1552.001
Credentials In Files
MalwareAzorult

Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.

T1552.001
Credentials In Files
ToolAADInternals

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

T1552.001
Credentials In Files
ToolEmpire

Empire can use various modules to search for files containing passwords.

T1552.001
Credentials In Files
ToolPoshC2

PoshC2 contains modules for searching for passwords in local and remote files.

T1552.001
Credentials In Files
ToolTruffleHog

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1552.001
Credentials In Files
ToolLaZagne

LaZagne can obtain credentials from chats, databases, mail, and WiFi.

T1552.001
Credentials In Files
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.