Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.001 Credentials In Files |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json. |
| T1552.001 Credentials In Files |
MalwareKali365 | Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys. |
| T1552.002 Credentials in Registry |
MalwareTrickBot | TrickBot has retrieved PuTTY credentials by querying the |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1552.002 Credentials in Registry |
MalwareValak | Valak can use the clientgrabber module to steal e-mail credentials from the Registry. |
| T1552.002 Credentials in Registry |
MalwareIceApple | IceApple can harvest credentials from local and remote host registries. |
| T1552.002 Credentials in Registry |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from the Registry. |
| T1552.002 Credentials in Registry |
ToolPowerSploit | PowerSploit has several modules that search the Windows Registry for stored credentials: |
| T1552.002 Credentials in Registry |
ToolReg | Reg may be used to find credentials in the Windows Registry. |
| T1552.003 Shell History |
MalwareKinsing | Kinsing has searched |
| T1552.003 Shell History |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners. |
| T1552.004 Private Keys |
MalwareMachete | Machete has scanned and looked for cryptographic keys and certificate file extensions. |
| T1552.004 Private Keys |
MalwareMafalda | Mafalda can collect a Chrome encryption key used to protect browser cookies. |
| T1552.004 Private Keys |
MalwareHildegard | Hildegard has searched for private keys in .ssh. |
| T1552.004 Private Keys |
MalwareFoggyWeb | FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server. |
| T1552.004 Private Keys |
MalwareTroll Stealer | Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems. |
| T1552.004 Private Keys |
MalwareEbury | Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| T1552.004 Private Keys |
MalwareKinsing | Kinsing has searched for private keys. |
| T1552.004 Private Keys |
MalwarejRAT | jRAT can steal keys for VPNs and cryptocurrency wallets. |
| T1552.004 Private Keys |
ToolAADInternals | AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers. |
| T1552.004 Private Keys |
ToolEmpire | Empire can use modules like |
| T1552.004 Private Keys |
ToolMimikatz | Mimikatz's |
| T1552.004 Private Keys |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys. |
| T1552.004 Private Keys |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh. |
| T1552.004 Private Keys |
MalwareCanisterWorm | CanisterWorm has gathered SSH private keys from the .ssh file. |
| T1552.005 Cloud Instance Metadata API |
MalwareHildegard | Hildegard has queried the Cloud Instance Metadata API for cloud credentials. |
| T1552.005 Cloud Instance Metadata API |
MalwareShai-Hulud | Shai-Hulud has queried the AWS and GCP metadata endpoints for instances and service credentials. |
| T1552.005 Cloud Instance Metadata API |
ToolTruffleHog | TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials. |
| T1552.005 Cloud Instance Metadata API |
ToolPeirates | Peirates can query the query AWS and GCP metadata APIs for secrets. |
| T1552.005 Cloud Instance Metadata API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API. |
| T1552.006 Group Policy Preferences |
MalwareMirrorStealer | MirrorStealer can target Group Policy Preferences for credentials. |
| T1552.006 Group Policy Preferences |
ToolSILENTTRINITY | SILENTTRINITY has a module that can extract cached GPP passwords. |
| T1552.006 Group Policy Preferences |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences. |
| T1552.007 Container API |
ToolPeirates | Peirates can query the Kubernetes API for secrets. |
| T1552.007 Container API |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can query the Kubernetes API for credentials. |
| T1552.007 Container API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators. |
| T1553 Subvert Trust Controls |
MalwareShai-Hulud | Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0. |
| T1553.001 Gatekeeper Bypass |
MalwareCuckoo Stealer | Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute. |
| T1553.001 Gatekeeper Bypass |
MalwareOSX_OCEANLOTUS.D | OSX_OCEANLOTUS.D uses the command |
| T1553.001 Gatekeeper Bypass |
MalwareMacMa | MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`. |
| T1553.001 Gatekeeper Bypass |
MalwareCoinTicker | CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag. |
| T1553.001 Gatekeeper Bypass |
MalwareXCSSET | XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13). |
| T1553.001 Gatekeeper Bypass |
MalwareOSX/Shlayer | If running with elevated privileges, OSX/Shlayer has used the |
| T1553.002 Code Signing |
MalwareTrickBot | TrickBot has come with a signed downloader component. |
| T1553.002 Code Signing |
MalwareBLINDINGCAN | BLINDINGCAN has been signed with code-signing certificates such as CodeRipper. |
| T1553.002 Code Signing |
MalwareStuxnet | Stuxnet used a digitally signed driver with a compromised Realtek certificate. |
| T1553.002 Code Signing |
MalwarePAKLOG | PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading. |
| T1553.002 Code Signing |
MalwareStrongPity | StrongPity has been signed with self-signed certificates. |
| T1553.002 Code Signing |
MalwareJanicab | Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.