Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1556 Modify Authentication Process |
MalwareDRYHOOK | DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`. |
| T1556 Modify Authentication Process |
ToolSILENTTRINITY | SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook. |
| T1556.001 Domain Controller Authentication |
MalwareSkeleton Key | Skeleton Key is used to patch an enterprise domain controller authentication process with a backdoor password. It allows adversaries to bypass the standard authentication system to use a defined password for all accounts authenticating to that domain controller. |
| T1556.002 Password Filter DLL |
MalwareRemsec | Remsec harvests plain-text credentials as a password filter registered on domain controllers. |
| T1556.003 Pluggable Authentication Modules |
MalwareSkidmap | Skidmap has the ability to replace the pam_unix.so file on an infected machine with its own malicious version that accepts a specific backdoor password for all users. |
| T1556.003 Pluggable Authentication Modules |
MalwareEbury | Ebury can deactivate PAM modules to tamper with the sshd configuration. |
| T1556.004 Network Device Authentication |
MalwareSYNful Knock | SYNful Knock has the capability to add its own custom backdoor password when it modifies the operating system of the affected network device. |
| T1556.004 Network Device Authentication |
MalwareDRYHOOK | DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in. |
| T1556.004 Network Device Authentication |
MalwareSLOWPULSE | SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password. |
| T1556.006 Multi-Factor Authentication |
MalwareSLOWPULSE | SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided. |
| T1556.006 Multi-Factor Authentication |
ToolAADInternals | The AADInternals `Set-AADIntUserMFA` command can be used to disable MFA for a specified user. |
| T1556.007 Hybrid Identity |
ToolAADInternals | AADInternals can inject a malicious DLL (`PTASpy`) into the `AzureADConnectAuthenticationAgentService` to backdoor Azure AD Pass-Through Authentication. |
| T1557 Adversary-in-the-Middle |
MalwareLine Runner | Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed. |
| T1557 Adversary-in-the-Middle |
MalwareDok | Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic. |
| T1557 Adversary-in-the-Middle |
ToolNPPSPY | NPPSPY opens a new network listener for the |
| T1557 Adversary-in-the-Middle |
Toolevilginx2 | evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens. |
| T1557 Adversary-in-the-Middle |
MalwareKali365 | Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolImpacket | Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolEmpire | Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPoshC2 | PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolResponder | Responder is used to poison name services to gather hashes and credentials from systems within a local network. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPupy | Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services. |
| T1558.001 Golden Ticket |
ToolSliver | Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets. |
| T1558.001 Golden Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use golden tickets. |
| T1558.001 Golden Ticket |
ToolMimikatz | Mimikatz's kerberos module can create golden tickets. |
| T1558.001 Golden Ticket |
ToolRubeus | Rubeus can forge a ticket-granting ticket. |
| T1558.002 Silver Ticket |
ToolAADInternals | AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account. |
| T1558.002 Silver Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use silver tickets. |
| T1558.002 Silver Ticket |
ToolMimikatz | Mimikatz's kerberos module can create silver tickets. |
| T1558.002 Silver Ticket |
ToolRubeus | Rubeus can create silver tickets. |
| T1558.003 Kerberoasting |
ToolSILENTTRINITY | SILENTTRINITY contains a module to conduct Kerberoasting. |
| T1558.003 Kerberoasting |
ToolPowerSploit | PowerSploit's |
| T1558.003 Kerberoasting |
ToolImpacket | Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat. |
| T1558.003 Kerberoasting |
ToolEmpire | Empire uses PowerSploit's |
| T1558.003 Kerberoasting |
ToolBrute Ratel C4 | Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking. |
| T1558.003 Kerberoasting |
ToolRubeus | Rubeus can use the `KerberosRequestorSecurityToken.GetRequest` method to request kerberoastable service tickets. |
| T1558.004 AS-REP Roasting |
ToolRubeus | Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting. |
| T1558.005 Ccache Files |
ToolImpacket | Impacket tools – such as |
| T1559 Inter-Process Communication |
MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| T1559 Inter-Process Communication |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID. |
| T1559 Inter-Process Communication |
MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| T1559 Inter-Process Communication |
MalwareTONESHELL | TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr. |
| T1559 Inter-Process Communication |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
| T1559 Inter-Process Communication |
MalwareHyperStack | HyperStack can connect to the IPC$ share on remote machines. |
| T1559 Inter-Process Communication |
MalwareRaspberry Robin | Raspberry Robin contains an embedded custom Tor network client that communicates with the primary payload via shared process memory. |
| T1559 Inter-Process Communication |
MalwareUroburos | Uroburos has the ability to move data between its kernel and user mode components, generally using named pipes. |
| T1559 Inter-Process Communication |
MalwareOilBooster | OilBooster can read the results of command line execution via an unnamed pipe connected to the process. |
| T1559 Inter-Process Communication |
MalwareCyclops Blink | Cyclops Blink has the ability to create a pipe to enable inter-process communication. |
| T1559 Inter-Process Communication |
MalwareROADSWEEP | ROADSWEEP can pipe command output to a targeted process. |
| T1559 Inter-Process Communication |
MalwareStealBit | StealBit can use interprocess communication (IPC) to enable the designation of multiple files for exfiltration in a scalable manner. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.