ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1134.003
Make and Impersonate Token
GroupBlackByte

BlackByte constructed a valid authentication token following Microsoft Exchange exploitation to allow for follow-on privileged command execution.

T1134.003
Make and Impersonate Token
GroupFIN13

FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.

T1134.003
Make and Impersonate Token
MalwareMafalda

Mafalda can create a token for a different user.

T1134.003
Make and Impersonate Token
MalwareCobalt Strike

Cobalt Strike can make tokens from known credentials.

T1134.003
Make and Impersonate Token
ToolSILENTTRINITY

SILENTTRINITY can make tokens from known credentials.

T1134.004
Parent PID Spoofing
MalwareDarkGate

DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer.

T1134.004
Parent PID Spoofing
MalwarePipeMon

PipeMon can use parent PID spoofing to elevate privileges.

T1134.004
Parent PID Spoofing
MalwareKONNI

KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`.

T1134.004
Parent PID Spoofing
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

T1134.005
SID-History Injection
ToolEmpire

Empire can add a SID-History to a user if on a domain controller.

T1134.005
SID-History Injection
ToolMimikatz

Mimikatz's MISC::AddSid module can append any SID or user/group account to a user's SID-History. Mimikatz also utilizes SID-History Injection to expand the scope of other components such as generated Kerberos Golden Tickets and DCSync beyond a single domain.

T1135
Network Share Discovery
CampaignC0015

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.

T1135
Network Share Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance.

T1135
Network Share Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors discovered network disks mounted to the system using netstat.

T1135
Network Share Discovery
CampaignLeviathan Australian Intrusions

Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions.

T1135
Network Share Discovery
GroupAPT38

APT38 has enumerated network shares on a compromised host.

T1135
Network Share Discovery
GroupBlackByte

BlackByte enumerated network shares on victim devices.

T1135
Network Share Discovery
GroupAPT41

APT41 used the net share command as part of network reconnaissance.

T1135
Network Share Discovery
GroupDragonfly

Dragonfly has identified and browsed file servers in the victim network, sometimes , viewing files pertaining to ICS or Supervisory Control and Data Acquisition (SCADA) systems.

T1135
Network Share Discovery
GroupAPT32

APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$.

T1135
Network Share Discovery
GroupAPT39

APT39 has used the post exploitation tool CrackMapExec to enumerate network shares.

T1135
Network Share Discovery
GroupTropic Trooper

Tropic Trooper used netview to scan target systems for shared resources.

T1135
Network Share Discovery
GroupAPT1

APT1 listed connected network shares.

T1135
Network Share Discovery
GroupDarkVishnya

DarkVishnya scanned the network for public shared folders.

T1135
Network Share Discovery
GroupChimera

Chimera has used net share and net view to identify network shares of interest.

T1135
Network Share Discovery
GroupMedusa Group

Medusa Group has identified network shares using `cmd.exe /c net share`.

T1135
Network Share Discovery
GroupTonto Team

Tonto Team has used tools such as NBTscan to enumerate network shares.

T1135
Network Share Discovery
GroupINC Ransom

INC Ransom has used Internet Explorer to view folders on other systems.

T1135
Network Share Discovery
GroupSowbug

Sowbug listed remote shared drives that were accessible from a victim.

T1135
Network Share Discovery
GroupWizard Spider

Wizard Spider has used the “net view” command to locate mapped network shares.

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1135
Network Share Discovery
MalwareQuietSieve

QuietSieve can identify and search networked drives for specific file name extensions.

T1135
Network Share Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about shares on remote hosts.

T1135
Network Share Discovery
MalwareStuxnet

Stuxnet enumerates the directories of a network resource.

T1135
Network Share Discovery
MalwareAvosLocker

AvosLocker has enumerated shared drives on a compromised network.

T1135
Network Share Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat and Net to discover network shares.

T1135
Network Share Discovery
MalwareSardonic

Sardonic has the ability to execute the `net view` command.

T1135
Network Share Discovery
MalwareRansomHub

RansomHub has the ability to target specific network shares for encryption.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1135
Network Share Discovery
MalwareBad Rabbit

Bad Rabbit enumerates open SMB shares on internal victim networks.

T1135
Network Share Discovery
MalwareEmotet

Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`.

T1135
Network Share Discovery
MalwareOlympic Destroyer

Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares.

T1135
Network Share Discovery
MalwareDUSTTRAP

DUSTTRAP can identify and enumerate victim system network shares.

T1135
Network Share Discovery
MalwareBADHATCH

BADHATCH can check a user's access to the C$ share on a compromised machine.

T1135
Network Share Discovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareWastedLocker

WastedLocker can identify network adjacent and accessible drives.

T1135
Network Share Discovery
MalwareInvisiMole

InvisiMole can gather network share information.

T1135
Network Share Discovery
MalwareWhisperGate

WhisperGate can enumerate connected remote logical drives.

T1135
Network Share Discovery
MalwareConti

Conti can enumerate remote open SMB network shares using NetShareEnum().

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.