Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1134.003 Make and Impersonate Token |
GroupBlackByte | BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution. |
| T1134.003 Make and Impersonate Token |
GroupFIN13 | FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation. |
| T1134.003 Make and Impersonate Token |
MalwareMafalda | Mafalda can create a token for a different user. |
| T1134.003 Make and Impersonate Token |
MalwareCobalt Strike | Cobalt Strike can make tokens from known credentials. |
| T1134.003 Make and Impersonate Token |
ToolSILENTTRINITY | SILENTTRINITY can make tokens from known credentials. |
| T1134.004 Parent PID Spoofing |
MalwareDarkGate | DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer. |
| T1134.004 Parent PID Spoofing |
MalwarePipeMon | PipeMon can use parent PID spoofing to elevate privileges. |
| T1134.004 Parent PID Spoofing |
MalwareKONNI | KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`. |
| T1134.004 Parent PID Spoofing |
MalwareCobalt Strike | Cobalt Strike can spawn processes with alternate PPIDs. |
| T1134.005 SID-History Injection |
ToolEmpire | Empire can add a SID-History to a user if on a domain controller. |
| T1134.005 SID-History Injection |
ToolMimikatz | Mimikatz's |
| T1135 Network Share Discovery |
CampaignC0015 | During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares. |
| T1135 Network Share Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance. |
| T1135 Network Share Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors discovered network disks mounted to the system using netstat. |
| T1135 Network Share Discovery |
CampaignLeviathan Australian Intrusions | Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions. |
| T1135 Network Share Discovery |
GroupAPT38 | APT38 has enumerated network shares on a compromised host. |
| T1135 Network Share Discovery |
GroupBlackByte | BlackByte enumerated network shares on victim devices. |
| T1135 Network Share Discovery |
GroupAPT41 | APT41 used the |
| T1135 Network Share Discovery |
GroupDragonfly | Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems. |
| T1135 Network Share Discovery |
GroupAPT32 | APT32 used the |
| T1135 Network Share Discovery |
GroupAPT39 | APT39 has used the post exploitation tool CrackMapExec to enumerate network shares. |
| T1135 Network Share Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1135 Network Share Discovery |
GroupAPT1 | APT1 listed connected network shares. |
| T1135 Network Share Discovery |
GroupDarkVishnya | DarkVishnya scanned the network for public shared folders. |
| T1135 Network Share Discovery |
GroupChimera | Chimera has used |
| T1135 Network Share Discovery |
GroupMedusa Group | Medusa Group has identified network shares using `cmd.exe /c net share`. |
| T1135 Network Share Discovery |
GroupTonto Team | Tonto Team has used tools such as NBTscan to enumerate network shares. |
| T1135 Network Share Discovery |
GroupINC Ransom | INC Ransom has used Internet Explorer to view folders on other systems. |
| T1135 Network Share Discovery |
GroupSowbug | Sowbug listed remote shared drives that were accessible from a victim. |
| T1135 Network Share Discovery |
GroupWizard Spider | Wizard Spider has used the “net view” command to locate mapped network shares. |
| T1135 Network Share Discovery |
GroupFIN13 | FIN13 has executed net view commands for enumeration of open shares on compromised machines. |
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1135 Network Share Discovery |
MalwareQuietSieve | QuietSieve can identify and search networked drives for specific file name extensions. |
| T1135 Network Share Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about shares on remote hosts. |
| T1135 Network Share Discovery |
MalwareStuxnet | Stuxnet enumerates the directories of a network resource. |
| T1135 Network Share Discovery |
MalwareAvosLocker | AvosLocker has enumerated shared drives on a compromised network. |
| T1135 Network Share Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat and Net to discover network shares. |
| T1135 Network Share Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net view` command. |
| T1135 Network Share Discovery |
MalwareRansomHub | RansomHub has the ability to target specific network shares for encryption. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1135 Network Share Discovery |
MalwareBad Rabbit | Bad Rabbit enumerates open SMB shares on internal victim networks. |
| T1135 Network Share Discovery |
MalwareEmotet | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. |
| T1135 Network Share Discovery |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares. |
| T1135 Network Share Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify and enumerate victim system network shares. |
| T1135 Network Share Discovery |
MalwareBADHATCH | BADHATCH can check a user's access to the C$ share on a compromised machine. |
| T1135 Network Share Discovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareWastedLocker | WastedLocker can identify network adjacent and accessible drives. |
| T1135 Network Share Discovery |
MalwareInvisiMole | InvisiMole can gather network share information. |
| T1135 Network Share Discovery |
MalwareWhisperGate | WhisperGate can enumerate connected remote logical drives. |
| T1135 Network Share Discovery |
MalwareConti | Conti can enumerate remote open SMB network shares using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.