ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwareUroburos

Uroburos can use custom communication methodologies that ride over common protocols including TCP, UDP, HTTP, SMTP, and DNS in order to blend with normal network traffic.

T1001.003
Protocol or Service Impersonation
MalwareBADCALL

BADCALL uses a FakeTLS method during C2.

T1001.003
Protocol or Service Impersonation
MalwareCobalt Strike

Cobalt Strike can leverage the HTTP protocol for C2 communication, while hiding the actual data in either an HTTP header, URI parameter, the transaction body, or appending it to the URI. Cobalt Strike has also added Host: ocsp.verisign.com to HTTP headers to mimic Online Certificate Status Protocol (OCSP) traffic.

T1001.003
Protocol or Service Impersonation
MalwareSUNBURST

SUNBURST masqueraded its network traffic as the Orion Improvement Program (OIP) protocol.

T1001.003
Protocol or Service Impersonation
MalwareFakeM

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

T1001.003
Protocol or Service Impersonation
MalwareFRAMESTING

FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions.

T1001.003
Protocol or Service Impersonation
MalwareHARDRAIN

HARDRAIN uses FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareStarProxy

StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server.

T1001.003
Protocol or Service Impersonation
MalwareFALLCHILL

FALLCHILL uses fake Transport Layer Security (TLS) to communicate with its C2 server.

T1003
OS Credential Dumping
MalwareCarbanak

Carbanak obtains Windows logon password details.

T1003
OS Credential Dumping
MalwareMgBot

MgBot includes modules for dumping and capturing credentials from process memory.

T1003
OS Credential Dumping
MalwareRevenge RAT

Revenge RAT has a plugin for credential harvesting.

T1003
OS Credential Dumping
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).

T1003
OS Credential Dumping
MalwareOnionDuke

OnionDuke steals credentials from its victims.

T1003
OS Credential Dumping
MalwareHOMEFRY

HOMEFRY can perform credential dumping.

T1003
OS Credential Dumping
MalwareTrojan.Karagany

Trojan.Karagany can dump passwords and save them into \ProgramData\Mail\MailAg\pwds.txt.

T1003.001
LSASS Memory
MalwareBad Rabbit

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.

T1003.001
LSASS Memory
MalwareGreyEnergy

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

T1003.001
LSASS Memory
MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1003.001
LSASS Memory
MalwareOlympic Destroyer

Olympic Destroyer contains a module that tries to obtain credentials from LSASS, similar to Mimikatz. These credentials are used with PsExec and Windows Management Instrumentation to help the malware propagate itself across a network.

T1003.001
LSASS Memory
MalwareMafalda

Mafalda can dump password hashes from `LSASS.exe`.

T1003.001
LSASS Memory
MalwareOkrum

Okrum was seen using MimikatzLite to perform credential dumping.

T1003.001
LSASS Memory
MalwareNotPetya

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1003.001
LSASS Memory
MalwarePysa

Pysa can perform OS credential dumping using Mimikatz.

T1003.001
LSASS Memory
MalwareCobalt Strike

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

T1003.001
LSASS Memory
MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1003.001
LSASS Memory
MalwarePoetRAT

PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials.

T1003.001
LSASS Memory
MalwareQilin

Qilin can employ an embedded Mimikatz module to dump LSASS memory.

T1003.001
LSASS Memory
MalwareCozyCar

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

T1003.001
LSASS Memory
MalwareLizar

Lizar can run Mimikatz to harvest credentials.

T1003.001
LSASS Memory
MalwareNet Crawler

Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems.

T1003.001
LSASS Memory
ToolSliver

Sliver has a built-in `procdump` command allowing for retrieval of memory from processes such as `lsass.exe` for credential harvesting.

T1003.001
LSASS Memory
ToolSILENTTRINITY

SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call.

T1003.001
LSASS Memory
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1003.001
LSASS Memory
ToolWindows Credential Editor

Windows Credential Editor can dump credentials.

T1003.001
LSASS Memory
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.001
LSASS Memory
ToolLslsass

Lslsass can dump active logon session password hashes from the lsass process.

T1003.001
LSASS Memory
ToolEmpire

Empire contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolPoshC2

PoshC2 contains an implementation of Mimikatz to gather credentials from memory.

T1003.001
LSASS Memory
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSASS Memory.

T1003.001
LSASS Memory
ToolLaZagne

LaZagne can perform credential dumping from memory to obtain account and password information.

T1003.001
LSASS Memory
ToolPupy

Pupy can execute Lazagne as well as Mimikatz using PowerShell.

T1003.002
Security Account Manager
MalwareCosmicDuke

CosmicDuke collects Windows account hashes.

T1003.002
Security Account Manager
MalwareHOPLIGHT

HOPLIGHT has the capability to harvest credentials and passwords from the SAM database.

T1003.002
Security Account Manager
MalwareRemsec

Remsec can dump the SAM database.

T1003.002
Security Account Manager
MalwareCobalt Strike

Cobalt Strike can recover hashed passwords.

T1003.002
Security Account Manager
MalwareIceApple

IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`.

T1003.002
Security Account Manager
MalwareCozyCar

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

T1003.002
Security Account Manager
MalwarePOWERTON

POWERTON has the ability to dump password hashes.

T1003.002
Security Account Manager
MalwareMivast

Mivast has the capability to gather NTLM password information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.