ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0363×

73 examples

TechniqueUsed byProcedure example
T1547.005
Security Support Provider
ToolEmpire

Empire can enumerate Security Support Providers (SSPs) as well as utilize PowerSploit's Install-SSP and Invoke-Mimikatz to install malicious SSPs and log authentication events.

T1547.009
Shortcut Modification
ToolEmpire

Empire can persist by modifying a .LNK file to include a backdoor.

T1548.002
Bypass User Account Control
ToolEmpire

Empire includes various modules to attempt to bypass UAC for escalation of privileges.

T1550.002
Pass the Hash
ToolEmpire

Empire can perform pass the hash attacks.

T1552.001
Credentials In Files
ToolEmpire

Empire can use various modules to search for files containing passwords.

T1552.004
Private Keys
ToolEmpire

Empire can use modules like Invoke-SessionGopher to extract private key and session information.

T1555.001
Keychain
ToolEmpire

Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential.

T1555.003
Credentials from Web Browsers
ToolEmpire

Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolEmpire

Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1558.001
Golden Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use golden tickets.

T1558.002
Silver Ticket
ToolEmpire

Empire can leverage its implementation of Mimikatz to obtain and use silver tickets.

T1558.003
Kerberoasting
ToolEmpire

Empire uses PowerSploit's Invoke-Kerberoast to request service tickets and return crackable ticket hashes.

T1560
Archive Collected Data
ToolEmpire

Empire can ZIP directories on the target system.

T1567.001
Exfiltration to Code Repository
ToolEmpire

Empire can use GitHub for data exfiltration.

T1567.002
Exfiltration to Cloud Storage
ToolEmpire

Empire can use Dropbox for data exfiltration.

T1569.002
Service Execution
ToolEmpire

Empire can use PsExec to execute a payload on a remote host.

T1573.002
Asymmetric Cryptography
ToolEmpire

Empire can use TLS to encrypt its C2 channel.

T1574.001
DLL
ToolEmpire

Empire contains modules that can discover and exploit various DLL hijacking opportunities.

T1574.004
Dylib Hijacking
ToolEmpire

Empire has a dylib hijacker module that generates a malicious dylib given the path to a legitimate dylib of a vulnerable application.

T1574.007
Path Interception by PATH Environment Variable
ToolEmpire

Empire contains modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.008
Path Interception by Search Order Hijacking
ToolEmpire

Empire contains modules that can discover and exploit search order hijacking vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolEmpire

Empire contains modules that can discover and exploit unquoted path vulnerabilities.

T1615
Group Policy Discovery
ToolEmpire

Empire includes various modules for enumerating Group Policy.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.