ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1556
Modify Authentication Process
MalwareDRYHOOK

DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`.

T1556
Modify Authentication Process
ToolSILENTTRINITY

SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook.

T1556.001
Domain Controller Authentication
MalwareSkeleton Key

Skeleton Key is used to patch an enterprise domain controller authentication process with a backdoor password. It allows adversaries to bypass the standard authentication system to use a defined password for all accounts authenticating to that domain controller.

T1556.002
Password Filter DLL
MalwareRemsec

Remsec harvests plain-text credentials as a password filter registered on domain controllers.

T1556.003
Pluggable Authentication Modules
MalwareSkidmap

Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users.

T1556.003
Pluggable Authentication Modules
MalwareEbury

Ebury can deactivate PAM modules to tamper with the sshd configuration.

T1556.004
Network Device Authentication
MalwareSYNful Knock

SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device.

T1556.004
Network Device Authentication
MalwareDRYHOOK

DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in.

T1556.004
Network Device Authentication
MalwareSLOWPULSE

SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password.

T1556.006
Multi-Factor Authentication
MalwareSLOWPULSE

SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided.

T1556.006
Multi-Factor Authentication
ToolAADInternals

The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user.

T1556.007
Hybrid Identity
ToolAADInternals

AADInternals can inject a malicious DLL (`PTASpy`) into the `AzureADConnectAuthenticationAgentService` to backdoor Azure AD Pass-Through Authentication.

T1557
Adversary-in-the-Middle
MalwareLine Runner

Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed.

T1557
Adversary-in-the-Middle
MalwareDok

Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic.

T1557
Adversary-in-the-Middle
ToolNPPSPY

NPPSPY opens a new network listener for the mpnotify.exe process that is typically contacted by the Winlogon process in Windows. A new, alternative RPC channel is set up with a malicious DLL recording plaintext credentials entered into Winlogon, effectively intercepting and redirecting the logon information.

T1557
Adversary-in-the-Middle
Toolevilginx2

evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens.

T1557
Adversary-in-the-Middle
MalwareKali365

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolImpacket

Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolEmpire

Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPoshC2

PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolResponder

Responder is used to poison name services to gather hashes and credentials from systems within a local network.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPupy

Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services.

T1558.001
Golden Ticket
ToolSliver

Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets.

T1558.001
Golden Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use golden tickets.

T1558.001
Golden Ticket
ToolMimikatz

Mimikatz's kerberos module can create golden tickets.

T1558.001
Golden Ticket
ToolRubeus

Rubeus can forge a ticket-granting ticket.

T1558.002
Silver Ticket
ToolAADInternals

AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account.

T1558.002
Silver Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use silver tickets.

T1558.002
Silver Ticket
ToolMimikatz

Mimikatz's kerberos module can create silver tickets.

T1558.002
Silver Ticket
ToolRubeus

Rubeus can create silver tickets.

T1558.003
Kerberoasting
ToolSILENTTRINITY

SILENTTRINITY contains a module to conduct Kerberoasting.

T1558.003
Kerberoasting
ToolPowerSploit

PowerSploit's Invoke-Kerberoast module can request service tickets and return crackable ticket hashes.

T1558.003
Kerberoasting
ToolImpacket

Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat.

T1558.003
Kerberoasting
ToolEmpire

Empire uses PowerSploit's Invoke-Kerberoast to request service tickets and return crackable ticket hashes.

T1558.003
Kerberoasting
ToolBrute Ratel C4

Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking.

T1558.003
Kerberoasting
ToolRubeus

Rubeus can use the `KerberosRequestorSecurityToken.GetRequest` method to request kerberoastable service tickets.

T1558.004
AS-REP Roasting
ToolRubeus

Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting.

T1558.005
Ccache Files
ToolImpacket

Impacket tools – such as getST.py or ticketer.py – can be used to steal or forge Kerberos tickets using ccache files given a password, hash, aesKey, or TGT.

T1559
Inter-Process Communication
MalwareNinja

Ninja can use pipes to redirect the standard input and the standard output.

T1559
Inter-Process Communication
MalwareRotaJakiro

When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID.

T1559
Inter-Process Communication
MalwareHavoc

The Havoc SMB demon can use named pipes for communication through a parent demon.

T1559
Inter-Process Communication
MalwareTONESHELL

TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr.

T1559
Inter-Process Communication
MalwareMedusa Ransomware

Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.

T1559
Inter-Process Communication
MalwareHyperStack

HyperStack can connect to the IPC$ share on remote machines.

T1559
Inter-Process Communication
MalwareRaspberry Robin

Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory.

T1559
Inter-Process Communication
MalwareUroburos

Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes.

T1559
Inter-Process Communication
MalwareOilBooster

OilBooster can read the results of command line execution via an unnamed pipe connected to the process.

T1559
Inter-Process Communication
MalwareCyclops Blink

Cyclops Blink has the ability to create a pipe to enable inter-process communication.

T1559
Inter-Process Communication
MalwareROADSWEEP

ROADSWEEP can pipe command output to a targeted process.

T1559
Inter-Process Communication
MalwareStealBit

StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.