ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1205.001
Port Knocking
GroupUNC3886

UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking.

T1205.001
Port Knocking
GroupPROMETHIUM

PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports.

T1205.001
Port Knocking
Malwarecd00r

cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication.

T1205.001
Port Knocking
MalwareMafalda

Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server.

T1205.001
Port Knocking
MalwareREPTILE

REPTILE has the ability to control compromised endpoints via port knocking.

T1205.001
Port Knocking
MalwaremetaMain

metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure.

T1205.002
Socket Filters
MalwareCASTLETAP

CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices.

T1205.002
Socket Filters
MalwareBPFDoor

BPFDoor uses BPF bytecode to attach a filter to a network socket to view ICMP, UDP, or TCP packets coming through ports 22 (ssh), 80 (http), and 443 (https). When BPFDoor finds a packet containing its “magic” bytes, it parses out two fields and forks itself. The parent process continues to monitor filtered traffic while the child process executes the instructions from the parsed fields.

T1205.002
Socket Filters
MalwarePenquin

Penquin installs a `TCP` and `UDP` filter on the `eth0` interface.

T1205.002
Socket Filters
MalwarePITSTOP

PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS.

T1207
Rogue Domain Controller
ToolMimikatz

Mimikatz’s LSADUMP::DCShadow module can be used to make AD updates by temporarily setting a computer to be a DC.

T1210
Exploitation of Remote Services
GroupDragonfly

Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers.

T1210
Exploitation of Remote Services
GroupmenuPass

menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupFIN7

FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.

T1210
Exploitation of Remote Services
GroupEmber Bear

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.

T1210
Exploitation of Remote Services
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

T1210
Exploitation of Remote Services
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

T1210
Exploitation of Remote Services
GroupTonto Team

Tonto Team has used EternalBlue exploits for lateral movement.

T1210
Exploitation of Remote Services
GroupEarth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1210
Exploitation of Remote Services
GroupThreat Group-3390

Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network.

T1210
Exploitation of Remote Services
MalwareTrickBot

TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll.

T1210
Exploitation of Remote Services
MalwareStuxnet

Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities.

T1210
Exploitation of Remote Services
MalwareBad Rabbit

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

T1210
Exploitation of Remote Services
MalwareEmotet

Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation.

T1210
Exploitation of Remote Services
MalwareInvisiMole

InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively.

T1210
Exploitation of Remote Services
MalwareLucifer

Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144).

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1210
Exploitation of Remote Services
MalwareConficker

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

T1210
Exploitation of Remote Services
MalwareWannaCry

WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network.

T1210
Exploitation of Remote Services
MalwareQakBot

QakBot can move laterally using worm-like functionality through exploitation of SMB.

T1210
Exploitation of Remote Services
ToolEmpire

Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers.

T1210
Exploitation of Remote Services
ToolPoshC2

PoshC2 contains a module for exploiting SMB via EternalBlue.

T1210
Exploitation of Remote Services
GroupShinyHunters

ShinyHunters has exploited vulnerabilities in remote services for lateral movement.

T1210
Exploitation of Remote Services
MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

T1211
Exploitation for Stealth
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

T1211
Exploitation for Stealth
GroupVelvet Ant

Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution.

T1212
Exploitation for Credential Access
CampaignLeviathan Australian Intrusions

Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials.

T1212
Exploitation for Credential Access
GroupUNC3886

UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB.

T1213
Data from Information Repositories
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations.

T1213
Data from Information Repositories
GroupAPT28

APT28 has collected files from various information repositories.

T1213
Data from Information Repositories
MalwareRaccoon Stealer

Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service.

T1213
Data from Information Repositories
MalwareTroll Stealer

Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems.

T1213.001
Confluence
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.

T1213.001
Confluence
ToolTruffleHog

TruffleHog has collected credentials and data associated with Confluence.

T1213.002
Sharepoint
CampaignC0027

During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

T1213.002
Sharepoint
GroupHAFNIUM

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint.

T1213.002
Sharepoint
GroupAkira

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

T1213.002
Sharepoint
GroupKe3chang

Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.