Real-world descriptions of how a group, tool or campaign used a technique.
82 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.002 Tool |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement. |
| T1588.002 Tool |
GroupStar Blizzard | Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity. |
| T1588.002 Tool |
GroupWhitefly | |
| T1588.002 Tool |
GroupLuminousMoth | LuminousMoth has obtained an ARP spoofing tool from GitHub. |
| T1588.002 Tool |
GroupAPT28 | APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder. |
| T1588.002 Tool |
GroupMetador | Metador has used Microsoft's Console Debugger in some of their operations. |
| T1588.002 Tool |
GroupAPT42 | APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection. |
| T1588.002 Tool |
GroupAPT-C-36 | APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor. |
| T1588.002 Tool |
GroupLazarus Group | Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1588.002 Tool |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of open source tools. |
| T1588.002 Tool |
GroupSilence | Silence has obtained and modified versions of publicly-available tools like Empire and PsExec. |
| T1588.002 Tool |
GroupThrip | Thrip has obtained and used tools such as Mimikatz and PsExec. |
| T1588.002 Tool |
GroupLAPSUS$ | LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations. |
| T1588.002 Tool |
GroupCobalt Group | Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete. |
| T1588.002 Tool |
GroupCopyKittens | CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities. |
| T1588.002 Tool |
GroupWizard Spider | Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts. |
| T1588.002 Tool |
GroupIndigoZebra | IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations. |
| T1588.002 Tool |
GroupInception | Inception has obtained and used open-source tools such as LaZagne. |
| T1588.002 Tool |
GroupVOID MANTICORE | VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities. |
| T1588.002 Tool |
GroupPlay | Play has used multiple tools for discovery and defense evasion purposes on compromised hosts. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
| T1588.002 Tool |
GroupWIRTE | WIRTE has obtained and used Empire and Rclone for post-exploitation activities. |
| T1588.002 Tool |
GroupMagic Hound | Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink. |
| T1588.002 Tool |
GroupThreat Group-3390 | Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor. |
| T1588.002 Tool |
GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
| T1588.002 Tool |
GroupFIN10 | FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments. |
| T1588.002 Tool |
GroupFIN8 | FIN8 has used open-source tools such as Impacket for targeting efforts. |
| T1588.002 Tool |
GroupFIN13 | FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts. |
| T1588.002 Tool |
GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
| T1588.002 Tool |
GroupPittyTiger | PittyTiger has obtained and used tools such as Mimikatz and gsecdump. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.