Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1548.003 Sudo and Sudo Caching |
MalwareCobalt Strike | Cobalt Strike can use |
| T1548.003 Sudo and Sudo Caching |
MalwareProton | Proton modifies the tty_tickets line in the sudoers file. |
| T1548.003 Sudo and Sudo Caching |
MalwareShai-Hulud | Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`. |
| T1548.003 Sudo and Sudo Caching |
MalwareDok | Dok adds |
| T1548.003 Sudo and Sudo Caching |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `sudo` for code execution. |
| T1548.003 Sudo and Sudo Caching |
MalwareCanisterWorm | CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command. |
| T1548.004 Elevated Execution with Prompt |
MalwareOSX/Shlayer | OSX/Shlayer can escalate privileges to root by asking the user for credentials. |
| T1548.006 TCC Manipulation |
MalwareXCSSET | For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access. |
| T1550 Use Alternate Authentication Material |
MalwareFoggyWeb | FoggyWeb can allow abuse of a compromised AD FS server's SAML token. |
| T1550.001 Application Access Token |
MalwareCreepyDrive | CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive. |
| T1550.001 Application Access Token |
MalwareShai-Hulud | Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts. |
| T1550.001 Application Access Token |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts. |
| T1550.001 Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to authenticate using stolen application access tokens. |
| T1550.001 Application Access Token |
MalwareCanisterWorm | CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope. |
| T1550.001 Application Access Token |
MalwareKali365 | Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules. |
| T1550.002 Pass the Hash |
MalwareBADHATCH | BADHATCH can perform pass the hash on compromised machines with x64 versions. |
| T1550.002 Pass the Hash |
MalwareHOPLIGHT | HOPLIGHT has been observed loading several APIs associated with Pass the Hash. |
| T1550.002 Pass the Hash |
MalwareCobalt Strike | Cobalt Strike can perform pass the hash. |
| T1550.002 Pass the Hash |
ToolEmpire | Empire can perform pass the hash attacks. |
| T1550.002 Pass the Hash |
ToolPoshC2 | PoshC2 has a number of modules that leverage pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
ToolPass-The-Hash Toolkit | Pass-The-Hash Toolkit can perform pass the hash. |
| T1550.002 Pass the Hash |
ToolMimikatz | Mimikatz's |
| T1550.002 Pass the Hash |
ToolCrackMapExec | CrackMapExec can pass the hash to authenticate via SMB. |
| T1550.003 Pass the Ticket |
MalwareSeaDuke | Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication. |
| T1550.003 Pass the Ticket |
ToolMimikatz | Mimikatz’s |
| T1550.003 Pass the Ticket |
ToolPupy | Pupy can also perform pass-the-ticket. |
| T1552 Unsecured Credentials |
MalwareDarkGate | DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe. |
| T1552 Unsecured Credentials |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1552 Unsecured Credentials |
ToolNPPSPY | NPPSPY captures credentials by recording them through an alternative network listener registered to the |
| T1552 Unsecured Credentials |
ToolPacu | Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates. |
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1552.001 Credentials In Files |
MalwareSmoke Loader | Smoke Loader searches for files named logins.json to parse for credentials. |
| T1552.001 Credentials In Files |
MalwareEmotet | Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user. |
| T1552.001 Credentials In Files |
MalwareHildegard | Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens. |
| T1552.001 Credentials In Files |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store. |
| T1552.001 Credentials In Files |
MalwareXTunnel | XTunnel is capable of accessing locally stored passwords on victims. |
| T1552.001 Credentials In Files |
Malwarepngdowner | If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.001 Credentials In Files |
MalwarePysa | Pysa has extracted credentials from the password database before encrypting the files. |
| T1552.001 Credentials In Files |
MalwareShai-Hulud | Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files. |
| T1552.001 Credentials In Files |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from configuration or support files. |
| T1552.001 Credentials In Files |
MalwarejRAT | jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk. |
| T1552.001 Credentials In Files |
MalwareAzorult | Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam. |
| T1552.001 Credentials In Files |
ToolAADInternals | AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine. |
| T1552.001 Credentials In Files |
ToolEmpire | Empire can use various modules to search for files containing passwords. |
| T1552.001 Credentials In Files |
ToolPoshC2 | PoshC2 contains modules for searching for passwords in local and remote files. |
| T1552.001 Credentials In Files |
ToolTruffleHog | TruffleHog has obtained credentials stored in config files and credential files in victim environments. |
| T1552.001 Credentials In Files |
ToolLaZagne | LaZagne can obtain credentials from chats, databases, mail, and WiFi. |
| T1552.001 Credentials In Files |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1552.001 Credentials In Files |
ToolQuasarRAT | QuasarRAT can obtain passwords from FTP clients. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.