Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1135 Network Share Discovery |
MalwareDiavol | Diavol has a `ENMDSKS` command to enumerates available network shares. |
| T1135 Network Share Discovery |
MalwareBlackCat | BlackCat has the ability to discover network shares on compromised networks. |
| T1135 Network Share Discovery |
MalwareIcedID | IcedID has used the `net view /all` command to show available shares. |
| T1135 Network Share Discovery |
MalwareShimRat | ShimRat can enumerate connected drives for infected host machines. |
| T1135 Network Share Discovery |
MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| T1135 Network Share Discovery |
MalwareFlagpro | Flagpro has been used to execute `net view` to discover mapped network shares. |
| T1135 Network Share Discovery |
MalwareHELLOKITTY | HELLOKITTY has the ability to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareBabuk | Babuk has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareCuba | Cuba can discover shared resources using the |
| T1135 Network Share Discovery |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use loop operations to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareClambling | Clambling has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareAkira | Akira can identify remote file shares for encryption. |
| T1135 Network Share Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify network shares on compromised systems. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1135 Network Share Discovery |
MalwareRoyal | Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`. |
| T1135 Network Share Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions. |
| T1135 Network Share Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareBazar | Bazar can enumerate shared drives on the domain. |
| T1135 Network Share Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can discover remote shares. |
| T1135 Network Share Discovery |
MalwareZebrocy | Zebrocy identifies network drives when they are added to victim systems. |
| T1135 Network Share Discovery |
MalwareCobalt Strike | Cobalt Strike can query shared drives on the local system. |
| T1135 Network Share Discovery |
MalwareRamsay | Ramsay can scan for network drives which may contain documents for collection. |
| T1135 Network Share Discovery |
MalwareKwampirs | Kwampirs collects a list of network shares with the command |
| T1135 Network Share Discovery |
MalwareClop | Clop can enumerate network shares. |
| T1135 Network Share Discovery |
MalwareLunarWeb | LunarWeb can identify shared resources in compromised environments. |
| T1135 Network Share Discovery |
MalwareQilin | Qilin has the ability to list network drives. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1135 Network Share Discovery |
MalwareINC Ransomware | INC Ransomware has the ability to check for shared network drives to encrypt. |
| T1135 Network Share Discovery |
MalwareFIVEHANDS | FIVEHANDS can enumerate network shares and mounted drives on a network. |
| T1135 Network Share Discovery |
MalwareOSInfo | OSInfo discovers shares on the network |
| T1135 Network Share Discovery |
MalwareBitPaymer | BitPaymer can search for network shares on the domain or workgroup using |
| T1135 Network Share Discovery |
ToolNet | The |
| T1135 Network Share Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate shares on a compromised host. |
| T1135 Network Share Discovery |
ToolEmpire | Empire can find shared drives on the local system. |
| T1135 Network Share Discovery |
ToolCrackMapExec | CrackMapExec can enumerate the shared folders and associated permissions for a targeted network. |
| T1135 Network Share Discovery |
ToolKoadic | Koadic can scan local network for open SMB. |
| T1135 Network Share Discovery |
ToolPupy | Pupy can list local and remote shared drives and folders over SMB. |
| T1136 Create Account |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`. |
| T1136 Create Account |
GroupIndrik Spider | Indrik Spider used |
| T1136 Create Account |
GroupSalt Typhoon | Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`. |
| T1136 Create Account |
GroupScattered Spider | Scattered Spider creates new user identities within the compromised organization. |
| T1136 Create Account |
MalwareLockBit 2.0 | LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| T1136.001 Local Account |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access. |
| T1136.001 Local Account |
GroupIndrik Spider | Indrik Spider has created local system accounts and has added the accounts to privileged groups. |
| T1136.001 Local Account |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1136.001 Local Account |
GroupKimsuky | Kimsuky has created accounts with |
| T1136.001 Local Account |
GroupAPT41 | APT41 has created user accounts. |
| T1136.001 Local Account |
GroupDragonfly | Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target. |
| T1136.001 Local Account |
GroupLeafminer | Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.