ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1552.001
Credentials In Files
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.

T1552.001
Credentials In Files
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.

T1552.001
Credentials In Files
MalwareKali365

Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys.

T1552.002
Credentials in Registry
MalwareTrickBot

TrickBot has retrieved PuTTY credentials by querying the Software\SimonTatham\Putty\Sessions registry key

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1552.002
Credentials in Registry
MalwareValak

Valak can use the clientgrabber module to steal e-mail credentials from the Registry.

T1552.002
Credentials in Registry
MalwareIceApple

IceApple can harvest credentials from local and remote host registries.

T1552.002
Credentials in Registry
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from the Registry.

T1552.002
Credentials in Registry
ToolPowerSploit

PowerSploit has several modules that search the Windows Registry for stored credentials: Get-UnattendedInstallFile, Get-Webconfig, Get-ApplicationHost, Get-SiteListPassword, Get-CachedGPPPassword, and Get-RegistryAutoLogon.

T1552.002
Credentials in Registry
ToolReg

Reg may be used to find credentials in the Windows Registry.

T1552.003
Shell History
MalwareKinsing

Kinsing has searched bash_history for credentials.

T1552.003
Shell History
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners.

T1552.004
Private Keys
MalwareMachete

Machete has scanned and looked for cryptographic keys and certificate file extensions.

T1552.004
Private Keys
MalwareMafalda

Mafalda can collect a Chrome encryption key used to protect browser cookies.

T1552.004
Private Keys
MalwareHildegard

Hildegard has searched for private keys in .ssh.

T1552.004
Private Keys
MalwareFoggyWeb

FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server.

T1552.004
Private Keys
MalwareTroll Stealer

Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems.

T1552.004
Private Keys
MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1552.004
Private Keys
MalwareKinsing

Kinsing has searched for private keys.

T1552.004
Private Keys
MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

T1552.004
Private Keys
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1552.004
Private Keys
ToolEmpire

Empire can use modules like Invoke-SessionGopher to extract private key and session information.

T1552.004
Private Keys
ToolMimikatz

Mimikatz's CRYPTO::Extract module can extract keys by interacting with Windows cryptographic application programming interface (API) functions.

T1552.004
Private Keys
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys.

T1552.004
Private Keys
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh.

T1552.004
Private Keys
MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

T1552.005
Cloud Instance Metadata API
MalwareHildegard

Hildegard has queried the Cloud Instance Metadata API for cloud credentials.

T1552.005
Cloud Instance Metadata API
MalwareShai-Hulud

Shai-Hulud has queried the AWS and GCP metadata endpoints for instances and service credentials.

T1552.005
Cloud Instance Metadata API
ToolTruffleHog

TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials.

T1552.005
Cloud Instance Metadata API
ToolPeirates

Peirates can query the query AWS and GCP metadata APIs for secrets.

T1552.005
Cloud Instance Metadata API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API.

T1552.006
Group Policy Preferences
MalwareMirrorStealer

MirrorStealer can target Group Policy Preferences for credentials.

T1552.006
Group Policy Preferences
ToolSILENTTRINITY

SILENTTRINITY has a module that can extract cached GPP passwords.

T1552.006
Group Policy Preferences
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences.

T1552.007
Container API
ToolPeirates

Peirates can query the Kubernetes API for secrets.

T1552.007
Container API
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can query the Kubernetes API for credentials.

T1552.007
Container API
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured API keys stored in container orchestrators.

T1553
Subvert Trust Controls
MalwareShai-Hulud

Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0.

T1553.001
Gatekeeper Bypass
MalwareCuckoo Stealer

Cuckoo Stealer can use `xattr -d com.apple.quarantine` to remove the quarantine flag attribute.

T1553.001
Gatekeeper Bypass
MalwareOSX_OCEANLOTUS.D

OSX_OCEANLOTUS.D uses the command xattr -d com.apple.quarantine to remove the quarantine file attribute used by Gatekeeper.

T1553.001
Gatekeeper Bypass
MalwareMacMa

MacMa has removed the `com.apple.quarantineattribute` from the dropped file, `$TMPDIR/airportpaird`.

T1553.001
Gatekeeper Bypass
MalwareCoinTicker

CoinTicker downloads the EggShell mach-o binary using curl, which does not set the quarantine flag.

T1553.001
Gatekeeper Bypass
MalwareXCSSET

XCSSET has dropped a malicious applet into an app's `.../Contents/MacOS/` folder of a previously launched app to bypass Gatekeeper's security checks on first launch apps (prior to macOS 13).

T1553.001
Gatekeeper Bypass
MalwareOSX/Shlayer

If running with elevated privileges, OSX/Shlayer has used the spctl command to disable Gatekeeper protection for a downloaded file. OSX/Shlayer can also leverage system links pointing to bash scripts in the downloaded DMG file to bypass Gatekeeper, a flaw patched in macOS 11.3 and later versions. OSX/Shlayer has been Notarized by Apple, resulting in successful passing of additional Gatekeeper checks.

T1553.002
Code Signing
MalwareTrickBot

TrickBot has come with a signed downloader component.

T1553.002
Code Signing
MalwareBLINDINGCAN

BLINDINGCAN has been signed with code-signing certificates such as CodeRipper.

T1553.002
Code Signing
MalwareStuxnet

Stuxnet used a digitally signed driver with a compromised Realtek certificate.

T1553.002
Code Signing
MalwarePAKLOG

PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading.

T1553.002
Code Signing
MalwareStrongPity

StrongPity has been signed with self-signed certificates.

T1553.002
Code Signing
MalwareJanicab

Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.