ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1135
Network Share Discovery
MalwareDiavol

Diavol has a `ENMDSKS` command to enumerates available network shares.

T1135
Network Share Discovery
MalwareBlackCat

BlackCat has the ability to discover network shares on compromised networks.

T1135
Network Share Discovery
MalwareIcedID

IcedID has used the `net view /all` command to show available shares.

T1135
Network Share Discovery
MalwareShimRat

ShimRat can enumerate connected drives for infected host machines.

T1135
Network Share Discovery
MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

T1135
Network Share Discovery
MalwareFlagpro

Flagpro has been used to execute `net view` to discover mapped network shares.

T1135
Network Share Discovery
MalwareHELLOKITTY

HELLOKITTY has the ability to enumerate network resources.

T1135
Network Share Discovery
MalwareBabuk

Babuk has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1135
Network Share Discovery
MalwareCuba

Cuba can discover shared resources using the NetShareEnum API call.

T1135
Network Share Discovery
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use loop operations to enumerate network resources.

T1135
Network Share Discovery
MalwareClambling

Clambling has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwareAkira

Akira can identify remote file shares for encryption.

T1135
Network Share Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify network shares on compromised systems.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1135
Network Share Discovery
MalwareRoyal

Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.

T1135
Network Share Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.

T1135
Network Share Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareBazar

Bazar can enumerate shared drives on the domain.

T1135
Network Share Discovery
MalwareLockBit 2.0

LockBit 2.0 can discover remote shares.

T1135
Network Share Discovery
MalwareZebrocy

Zebrocy identifies network drives when they are added to victim systems.

T1135
Network Share Discovery
MalwareCobalt Strike

Cobalt Strike can query shared drives on the local system.

T1135
Network Share Discovery
MalwareRamsay

Ramsay can scan for network drives which may contain documents for collection.

T1135
Network Share Discovery
MalwareKwampirs

Kwampirs collects a list of network shares with the command net share.

T1135
Network Share Discovery
MalwareClop

Clop can enumerate network shares.

T1135
Network Share Discovery
MalwareLunarWeb

LunarWeb can identify shared resources in compromised environments.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1135
Network Share Discovery
MalwareINC Ransomware

INC Ransomware has the ability to check for shared network drives to encrypt.

T1135
Network Share Discovery
MalwareFIVEHANDS

FIVEHANDS can enumerate network shares and mounted drives on a network.

T1135
Network Share Discovery
MalwareOSInfo

OSInfo discovers shares on the network

T1135
Network Share Discovery
MalwareBitPaymer

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

T1135
Network Share Discovery
ToolNet

The net view \\remotesystem and net share commands in Net can be used to find shared drives and directories on remote and local systems respectively.

T1135
Network Share Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate shares on a compromised host.

T1135
Network Share Discovery
ToolEmpire

Empire can find shared drives on the local system.

T1135
Network Share Discovery
ToolCrackMapExec

CrackMapExec can enumerate the shared folders and associated permissions for a targeted network.

T1135
Network Share Discovery
ToolKoadic

Koadic can scan local network for open SMB.

T1135
Network Share Discovery
ToolPupy

Pupy can list local and remote shared drives and folders over SMB.

T1136
Create Account
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`.

T1136
Create Account
GroupIndrik Spider

Indrik Spider used wmic.exe to add a new user to the system.

T1136
Create Account
GroupSalt Typhoon

Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`.

T1136
Create Account
GroupScattered Spider

Scattered Spider creates new user identities within the compromised organization.

T1136
Create Account
MalwareLockBit 2.0

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

T1136.001
Local Account
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access.

T1136.001
Local Account
GroupIndrik Spider

Indrik Spider has created local system accounts and has added the accounts to privileged groups.

T1136.001
Local Account
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1136.001
Local Account
GroupKimsuky

Kimsuky has created accounts with net user.

T1136.001
Local Account
GroupAPT41

APT41 has created user accounts.

T1136.001
Local Account
GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

T1136.001
Local Account
GroupLeafminer

Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.