ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1588.002×

82 examples

TechniqueUsed byProcedure example
T1588.002
Tool
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement.

T1588.002
Tool
GroupStar Blizzard

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.

T1588.002
Tool
GroupWhitefly

Whitefly has obtained and used tools such as Mimikatz.

T1588.002
Tool
GroupLuminousMoth

LuminousMoth has obtained an ARP spoofing tool from GitHub.

T1588.002
Tool
GroupAPT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

T1588.002
Tool
GroupMetador

Metador has used Microsoft's Console Debugger in some of their operations.

T1588.002
Tool
GroupAPT42

APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection.

T1588.002
Tool
GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

T1588.002
Tool
GroupLazarus Group

Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP.

T1588.002
Tool
GroupINC Ransom

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.

T1588.002
Tool
GroupEarth Lusca

Earth Lusca has acquired and used a variety of open source tools.

T1588.002
Tool
GroupSilence

Silence has obtained and modified versions of publicly-available tools like Empire and PsExec.

T1588.002
Tool
GroupThrip

Thrip has obtained and used tools such as Mimikatz and PsExec.

T1588.002
Tool
GroupLAPSUS$

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.

T1588.002
Tool
GroupCobalt Group

Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.

T1588.002
Tool
GroupCopyKittens

CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities.

T1588.002
Tool
GroupWizard Spider

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

T1588.002
Tool
GroupIndigoZebra

IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.

T1588.002
Tool
GroupInception

Inception has obtained and used open-source tools such as LaZagne.

T1588.002
Tool
GroupVOID MANTICORE

VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.

T1588.002
Tool
GroupPlay

Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.

T1588.002
Tool
GroupHEXANE

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.

T1588.002
Tool
GroupWIRTE

WIRTE has obtained and used Empire and Rclone for post-exploitation activities.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1588.002
Tool
GroupThreat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.

T1588.002
Tool
GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

T1588.002
Tool
GroupFIN10

FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.

T1588.002
Tool
GroupFIN8

FIN8 has used open-source tools such as Impacket for targeting efforts.

T1588.002
Tool
GroupFIN13

FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts.

T1588.002
Tool
GroupAPT19

APT19 has obtained and used publicly-available tools like Empire.

T1588.002
Tool
GroupPittyTiger

PittyTiger has obtained and used tools such as Mimikatz and gsecdump.

T1588.002
Tool
GroupShinyHunters

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.