ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1548.002
Bypass User Account Control
MalwareUPPERCUT

UPPERCUT contains functionality to bypass UAC.

T1548.002
Bypass User Account Control
MalwareWarzoneRAT

WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module.

T1548.002
Bypass User Account Control
ToolUACMe

UACMe contains many methods for bypassing Windows User Account Control on multiple versions of the operating system.

T1548.002
Bypass User Account Control
ToolSliver

Sliver can leverage multiple techniques to bypass User Account Control (UAC) on Windows systems.

T1548.002
Bypass User Account Control
ToolSILENTTRINITY

SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension.

T1548.002
Bypass User Account Control
ToolEmpire

Empire includes various modules to attempt to bypass UAC for escalation of privileges.

T1548.002
Bypass User Account Control
ToolPoshC2

PoshC2 can utilize multiple methods to bypass UAC.

T1548.002
Bypass User Account Control
ToolCSPY Downloader

CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.

T1548.002
Bypass User Account Control
ToolRemcos

Remcos has a command for UAC bypassing.

T1548.002
Bypass User Account Control
ToolKoadic

Koadic has 2 methods for elevating integrity. It can bypass UAC through `eventvwr.exe` and `sdclt.exe`.

T1548.002
Bypass User Account Control
ToolPupy

Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths.

T1548.002
Bypass User Account Control
ToolQuasarRAT

QuasarRAT can generate a UAC pop-up Window to prompt the target user to run a command as the administrator.

T1548.003
Sudo and Sudo Caching
MalwareCobalt Strike

Cobalt Strike can use sudo to run a command.

T1548.003
Sudo and Sudo Caching
MalwareProton

Proton modifies the tty_tickets line in the sudoers file.

T1548.003
Sudo and Sudo Caching
MalwareShai-Hulud

Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`.

T1548.003
Sudo and Sudo Caching
MalwareDok

Dok adds admin ALL=(ALL) NOPASSWD: ALL to the /etc/sudoers file.

T1548.003
Sudo and Sudo Caching
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `sudo` for code execution.

T1548.003
Sudo and Sudo Caching
MalwareCanisterWorm

CanisterWorm has checked if the current user is root. If it is, CanisterWorm will wipe the system using `rm –rf / --no-preserve-root`. If it is not, CanisterWorm will try passwordless sudo and will run the same command.

T1548.004
Elevated Execution with Prompt
MalwareOSX/Shlayer

OSX/Shlayer can escalate privileges to root by asking the user for credentials.

T1548.006
TCC Manipulation
MalwareXCSSET

For several modules, XCSSET attempts to access or list the contents of user folders such as Desktop, Downloads, and Documents. If the folder does not exist or access is denied, it enters a loop where it resets the TCC database and retries access.

T1550
Use Alternate Authentication Material
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used forged SAML tokens that allowed the actors to impersonate users and bypass MFA, enabling APT29 to access enterprise cloud applications and services.

T1550
Use Alternate Authentication Material
MalwareFoggyWeb

FoggyWeb can allow abuse of a compromised AD FS server's SAML token.

T1550.001
Application Access Token
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised service principals to make changes to the Office 365 environment.

T1550.001
Application Access Token
GroupHAFNIUM

HAFNIUM has abused service principals with administrative permissions for data exfiltration.

T1550.001
Application Access Token
GroupAPT28

APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail.

T1550.001
Application Access Token
MalwareCreepyDrive

CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive.

T1550.001
Application Access Token
MalwareShai-Hulud

Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts.

T1550.001
Application Access Token
ToolPeirates

Peirates can use stolen service account tokens to perform its operations. It also enables adversaries to switch between valid service accounts.

T1550.001
Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to authenticate using stolen application access tokens.

T1550.001
Application Access Token
MalwareCanisterWorm

CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope.

T1550.001
Application Access Token
GroupTeamPCP

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.

T1550.001
Application Access Token
GroupShinyHunters

ShinyHunters has used stolen OAuth keys to access cloud infrastructure and to bypass two-factor authentication.

T1550.001
Application Access Token
MalwareKali365

Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules.

T1550.002
Pass the Hash
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally.

T1550.002
Pass the Hash
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems.

T1550.002
Pass the Hash
CampaignNight Dragon

During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.

T1550.002
Pass the Hash
GroupGALLIUM

GALLIUM used dumped hashes to authenticate to other machines via pass the hash.

T1550.002
Pass the Hash
GroupKimsuky

Kimsuky has used pass the hash for authentication to remote access software used in C2.

T1550.002
Pass the Hash
GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

T1550.002
Pass the Hash
GroupAPT32

APT32 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

T1550.002
Pass the Hash
GroupAPT1

The APT1 group is known to have used pass the hash.

T1550.002
Pass the Hash
GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

T1550.002
Pass the Hash
GroupEmber Bear

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.

T1550.002
Pass the Hash
GroupAPT28

APT28 has used pass the hash for lateral movement.

T1550.002
Pass the Hash
GroupWizard Spider

Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.

T1550.002
Pass the Hash
GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

T1550.002
Pass the Hash
MalwareBADHATCH

BADHATCH can perform pass the hash on compromised machines with x64 versions.

T1550.002
Pass the Hash
MalwareHOPLIGHT

HOPLIGHT has been observed loading several APIs associated with Pass the Hash.

T1550.002
Pass the Hash
MalwareCobalt Strike

Cobalt Strike can perform pass the hash.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.