Real-world descriptions of how a group, tool or campaign used a technique.
73 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.005 Security Support Provider |
ToolEmpire | Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's |
| T1547.009 Shortcut Modification |
ToolEmpire | Empire can persist by modifying a .LNK file to include a backdoor. |
| T1548.002 Bypass User Account Control |
ToolEmpire | Empire includes various modules to attempt to bypass UAC for escalation of privileges. |
| T1550.002 Pass the Hash |
ToolEmpire | Empire can perform pass the hash attacks. |
| T1552.001 Credentials In Files |
ToolEmpire | Empire can use various modules to search for files containing passwords. |
| T1552.004 Private Keys |
ToolEmpire | Empire can use modules like |
| T1555.001 Keychain |
ToolEmpire | Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential. |
| T1555.003 Credentials from Web Browsers |
ToolEmpire | Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolEmpire | Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1558.001 Golden Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use golden tickets. |
| T1558.002 Silver Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use silver tickets. |
| T1558.003 Kerberoasting |
ToolEmpire | Empire uses PowerSploit's |
| T1560 Archive Collected Data |
ToolEmpire | Empire can ZIP directories on the target system. |
| T1567.001 Exfiltration to Code Repository |
ToolEmpire | Empire can use GitHub for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
ToolEmpire | Empire can use Dropbox for data exfiltration. |
| T1569.002 Service Execution |
ToolEmpire | Empire can use PsExec to execute a payload on a remote host. |
| T1573.002 Asymmetric Cryptography |
ToolEmpire | Empire can use TLS to encrypt its C2 channel. |
| T1574.001 DLL |
ToolEmpire | Empire contains modules that can discover and exploit various DLL hijacking opportunities. |
| T1574.004 Dylib Hijacking |
ToolEmpire | Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application. |
| T1574.007 Path Interception by PATH Environment Variable |
ToolEmpire | Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolEmpire | Empire contains modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolEmpire | Empire contains modules that can discover and exploit unquoted path vulnerabilities. |
| T1615 Group Policy Discovery |
ToolEmpire | Empire includes various modules for enumerating Group Policy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.