Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1548.002 Bypass User Account Control |
MalwareUPPERCUT | UPPERCUT contains functionality to bypass UAC. |
| T1548.002 Bypass User Account Control |
MalwareWarzoneRAT | WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module. |
| T1548.002 Bypass User Account Control |
ToolUACMe | UACMe contains many methods for bypassing Windows User Account Control on multiple versions of the operating system. |
| T1548.002 Bypass User Account Control |
ToolSliver | Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems. |
| T1548.002 Bypass User Account Control |
ToolSILENTTRINITY | SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension. |
| T1548.002 Bypass User Account Control |
ToolEmpire | Empire includes various modules to attempt to bypass UAC for escalation of privileges. |
| T1548.002 Bypass User Account Control |
ToolPoshC2 | PoshC2 can utilize multiple methods to bypass UAC. |
| T1548.002 Bypass User Account Control |
ToolCSPY Downloader | CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges. |
| T1548.002 Bypass User Account Control |
ToolRemcos | Remcos has a command for UAC bypassing. |
| T1548.002 Bypass User Account Control |
ToolKoadic | Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`. |
| T1548.002 Bypass User Account Control |
ToolPupy | Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths. |
| T1548.002 Bypass User Account Control |
ToolQuasarRAT | QuasarRAT can generate a UAC pop-up Window to prompt the target user to run a command as the administrator. |
| T1548.003 Sudo and Sudo Caching |
MalwareCobalt Strike | Cobalt Strike can use |
| T1548.003 Sudo and Sudo Caching |
MalwareProton | Proton modifies the tty_tickets line in the sudoers file. |
| T1548.003 Sudo and Sudo Caching |
MalwareShai-Hulud | Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`. |
| T1548.003 Sudo and Sudo Caching |
MalwareDok | Dok adds |
| T1548.003 Sudo and Sudo Caching |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `sudo` for code execution. |
| T1548.003 Sudo and Sudo Caching |
MalwareCanisterWorm | CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command. |
| T1548.004 Elevated Execution with Prompt |
MalwareOSX/Shlayer | OSX/Shlayer can escalate privileges to root by asking the user for credentials. |
| T1548.006 TCC Manipulation |
MalwareXCSSET | For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access. |
| T1550 Use Alternate Authentication Material |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services. |
| T1550 Use Alternate Authentication Material |
MalwareFoggyWeb | FoggyWeb can allow abuse of a compromised AD FS server's SAML token. |
| T1550.001 Application Access Token |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment. |
| T1550.001 Application Access Token |
GroupHAFNIUM | HAFNIUM has abused service principals with administrative permissions for data exfiltration. |
| T1550.001 Application Access Token |
GroupAPT28 | APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail. |
| T1550.001 Application Access Token |
MalwareCreepyDrive | CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive. |
| T1550.001 Application Access Token |
MalwareShai-Hulud | Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts. |
| T1550.001 Application Access Token |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts. |
| T1550.001 Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to authenticate using stolen application access tokens. |
| T1550.001 Application Access Token |
MalwareCanisterWorm | CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope. |
| T1550.001 Application Access Token |
GroupTeamPCP | TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments. |
| T1550.001 Application Access Token |
GroupShinyHunters | ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication. |
| T1550.001 Application Access Token |
MalwareKali365 | Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules. |
| T1550.002 Pass the Hash |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally. |
| T1550.002 Pass the Hash |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems. |
| T1550.002 Pass the Hash |
CampaignNight Dragon | During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers. |
| T1550.002 Pass the Hash |
GroupGALLIUM | GALLIUM used dumped hashes to authenticate to other machines via pass the hash. |
| T1550.002 Pass the Hash |
GroupKimsuky | Kimsuky has used pass the hash for authentication to remote access software used in C2. |
| T1550.002 Pass the Hash |
GroupAPT41 | APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes. |
| T1550.002 Pass the Hash |
GroupAPT32 | APT32 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| T1550.002 Pass the Hash |
GroupAPT1 | The APT1 group is known to have used pass the hash. |
| T1550.002 Pass the Hash |
GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| T1550.002 Pass the Hash |
GroupEmber Bear | Ember Bear has used pass-the-hash techniques for lateral movement in victim environments. |
| T1550.002 Pass the Hash |
GroupAPT28 | APT28 has used pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
GroupWizard Spider | Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally. |
| T1550.002 Pass the Hash |
GroupFIN13 | FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment. |
| T1550.002 Pass the Hash |
MalwareBADHATCH | BADHATCH can perform pass the hash on compromised machines with x64 versions. |
| T1550.002 Pass the Hash |
MalwareHOPLIGHT | HOPLIGHT has been observed loading several APIs associated with Pass the Hash. |
| T1550.002 Pass the Hash |
MalwareCobalt Strike | Cobalt Strike can perform pass the hash. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.