Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1205.001 Port Knocking |
GroupUNC3886 | UNC3886 maintained persistence on FortiGate Firewalls through ICMP port knocking. |
| T1205.001 Port Knocking |
GroupPROMETHIUM | PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports. |
| T1205.001 Port Knocking |
Malwarecd00r | cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication. |
| T1205.001 Port Knocking |
MalwareMafalda | Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server. |
| T1205.001 Port Knocking |
MalwareREPTILE | REPTILE has the ability to control compromised endpoints via port knocking. |
| T1205.001 Port Knocking |
MalwaremetaMain | metaMain has authenticated itself to a different implant, Cryshell, through a port knocking and handshake procedure. |
| T1205.002 Socket Filters |
MalwareCASTLETAP | CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices. |
| T1205.002 Socket Filters |
MalwareBPFDoor | BPFDoor uses BPF bytecode to attach a filter to a network socket to view ICMP, UDP, or TCP packets coming through ports 22 (ssh), 80 (http), and 443 (https). When BPFDoor finds a packet containing its “magic” bytes, it parses out two fields and forks itself. The parent process continues to monitor filtered traffic while the child process executes the instructions from the parsed fields. |
| T1205.002 Socket Filters |
MalwarePenquin | Penquin installs a `TCP` and `UDP` filter on the `eth0` interface. |
| T1205.002 Socket Filters |
MalwarePITSTOP | PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS. |
| T1207 Rogue Domain Controller |
ToolMimikatz | Mimikatz’s |
| T1210 Exploitation of Remote Services |
GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| T1210 Exploitation of Remote Services |
GroupmenuPass | menuPass has used tools to exploit the ZeroLogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| T1210 Exploitation of Remote Services |
GroupEmber Bear | Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations. |
| T1210 Exploitation of Remote Services |
GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| T1210 Exploitation of Remote Services |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| T1210 Exploitation of Remote Services |
GroupTonto Team | Tonto Team has used EternalBlue exploits for lateral movement. |
| T1210 Exploitation of Remote Services |
GroupEarth Lusca | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472). |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1210 Exploitation of Remote Services |
GroupThreat Group-3390 | Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network. |
| T1210 Exploitation of Remote Services |
MalwareTrickBot | TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll. |
| T1210 Exploitation of Remote Services |
MalwareStuxnet | Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities. |
| T1210 Exploitation of Remote Services |
MalwareBad Rabbit | Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks. |
| T1210 Exploitation of Remote Services |
MalwareEmotet | Emotet has been seen exploiting SMB via a vulnerability exploit like EternalBlue (MS17-010) to achieve lateral movement and propagation. |
| T1210 Exploitation of Remote Services |
MalwareInvisiMole | InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively. |
| T1210 Exploitation of Remote Services |
MalwareLucifer | Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144). |
| T1210 Exploitation of Remote Services |
MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1210 Exploitation of Remote Services |
MalwareConficker | Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| T1210 Exploitation of Remote Services |
MalwareWannaCry | WannaCry uses an exploit in SMBv1 to spread itself to other remote systems on a network. |
| T1210 Exploitation of Remote Services |
MalwareQakBot | QakBot can move laterally using worm-like functionality through exploitation of SMB. |
| T1210 Exploitation of Remote Services |
ToolEmpire | Empire has a limited number of built-in modules for exploiting remote SMB, JBoss, and Jenkins servers. |
| T1210 Exploitation of Remote Services |
ToolPoshC2 | PoshC2 contains a module for exploiting SMB via EternalBlue. |
| T1210 Exploitation of Remote Services |
GroupShinyHunters | ShinyHunters has exploited vulnerabilities in remote services for lateral movement. |
| T1210 Exploitation of Remote Services |
MalwareFlame | Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
| T1211 Exploitation for Stealth |
GroupAPT28 | APT28 has used CVE-2015-4902 to bypass security features. |
| T1211 Exploitation for Stealth |
GroupVelvet Ant | Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution. |
| T1212 Exploitation for Credential Access |
CampaignLeviathan Australian Intrusions | Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials. |
| T1212 Exploitation for Credential Access |
GroupUNC3886 | UNC3886 exploited CVE-2022-22948 in VMware vCenter to obtain encrypted credentials from the vCenter postgresDB. |
| T1213 Data from Information Repositories |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 accessed victims' internal knowledge repositories (wikis) to view sensitive corporate information on products, services, and internal business operations. |
| T1213 Data from Information Repositories |
GroupAPT28 | APT28 has collected files from various information repositories. |
| T1213 Data from Information Repositories |
MalwareRaccoon Stealer | Raccoon Stealer gathers information from repositories associated with cryptocurrency wallets and the Telegram messaging service. |
| T1213 Data from Information Repositories |
MalwareTroll Stealer | Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems. |
| T1213.001 Confluence |
GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials. |
| T1213.001 Confluence |
ToolTruffleHog | TruffleHog has collected credentials and data associated with Confluence. |
| T1213.002 Sharepoint |
CampaignC0027 | During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides. |
| T1213.002 Sharepoint |
GroupHAFNIUM | HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint. |
| T1213.002 Sharepoint |
GroupAkira | Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity. |
| T1213.002 Sharepoint |
GroupKe3chang | Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.