ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1550.002
Pass the Hash
ToolEmpire

Empire can perform pass the hash attacks.

T1550.002
Pass the Hash
ToolPoshC2

PoshC2 has a number of modules that leverage pass the hash for lateral movement.

T1550.002
Pass the Hash
ToolPass-The-Hash Toolkit

Pass-The-Hash Toolkit can perform pass the hash.

T1550.002
Pass the Hash
ToolMimikatz

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

T1550.002
Pass the Hash
ToolCrackMapExec

CrackMapExec can pass the hash to authenticate via SMB.

T1550.003
Pass the Ticket
GroupAPT32

APT32 successfully gained remote access by using pass the ticket.

T1550.003
Pass the Ticket
GroupAPT29

APT29 used Kerberos ticket attacks for lateral movement.

T1550.003
Pass the Ticket
GroupBRONZE BUTLER

BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access.

T1550.003
Pass the Ticket
MalwareSeaDuke

Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication.

T1550.003
Pass the Ticket
ToolMimikatz

Mimikatz’s LSADUMP::DCSync and KERBEROS::PTT modules implement the three steps required to extract the krbtgt account hash and create/use Kerberos tickets.

T1550.003
Pass the Ticket
ToolPupy

Pupy can also perform pass-the-ticket.

T1550.004
Web Session Cookie
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

T1550.004
Web Session Cookie
GroupStar Blizzard

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.

T1552
Unsecured Credentials
CampaignLeviathan Australian Intrusions

Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions.

T1552
Unsecured Credentials
GroupVolt Typhoon

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.

T1552
Unsecured Credentials
MalwareDarkGate

DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe.

T1552
Unsecured Credentials
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1552
Unsecured Credentials
ToolNPPSPY

NPPSPY captures credentials by recording them through an alternative network listener registered to the mpnotify.exe process, allowing for cleartext recording of logon information.

T1552
Unsecured Credentials
ToolPacu

Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates.

T1552.001
Credentials In Files
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads.

T1552.001
Credentials In Files
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to extract authentication certificates stored in system configuration files across compromised environments.

T1552.001
Credentials In Files
CampaignLeviathan Australian Intrusions

Leviathan gathered credentials stored in files related to Building Management System (BMS) operations during Leviathan Australian Intrusions.

T1552.001
Credentials In Files
GroupIndrik Spider

Indrik Spider has searched files to obtain and exfiltrate credentials.

T1552.001
Credentials In Files
GroupAPT3

APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.

T1552.001
Credentials In Files
GroupKimsuky

Kimsuky has used tools that are capable of obtaining credentials from saved mail.

T1552.001
Credentials In Files
GroupMuddyWater

MuddyWater has run a tool that steals passwords saved in victim email.

T1552.001
Credentials In Files
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1552.001
Credentials In Files
GroupTeamTNT

TeamTNT has searched for unsecured AWS credentials and Docker API credentials.

T1552.001
Credentials In Files
GroupScattered Spider

Scattered Spider Spider searches for credential storage documentation on a compromised host.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1552.001
Credentials In Files
GroupTA505

TA505 has used malware to gather credentials from FTP clients and Outlook.

T1552.001
Credentials In Files
GroupRedCurl

RedCurl used LaZagne to obtain passwords in files.

T1552.001
Credentials In Files
GroupEmber Bear

Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials.

T1552.001
Credentials In Files
GroupFox Kitten

Fox Kitten has accessed files to gain valid credentials.

T1552.001
Credentials In Files
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1552.001
Credentials In Files
GroupFIN13

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.

T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1552.001
Credentials In Files
MalwareSmoke Loader

Smoke Loader searches for files named logins.json to parse for credentials.

T1552.001
Credentials In Files
MalwareEmotet

Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user.

T1552.001
Credentials In Files
MalwareHildegard

Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens.

T1552.001
Credentials In Files
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.

T1552.001
Credentials In Files
MalwareXTunnel

XTunnel is capable of accessing locally stored passwords on victims.

T1552.001
Credentials In Files
Malwarepngdowner

If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.001
Credentials In Files
MalwarePysa

Pysa has extracted credentials from the password database before encrypting the files.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1552.001
Credentials In Files
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from configuration or support files.

T1552.001
Credentials In Files
MalwarejRAT

jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk.

T1552.001
Credentials In Files
MalwareAzorult

Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.

T1552.001
Credentials In Files
ToolAADInternals

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.