Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1550.002 Pass the Hash |
ToolEmpire | Empire can perform pass the hash attacks. |
| T1550.002 Pass the Hash |
ToolPoshC2 | PoshC2 has a number of modules that leverage pass the hash for lateral movement. |
| T1550.002 Pass the Hash |
ToolPass-The-Hash Toolkit | Pass-The-Hash Toolkit can perform pass the hash. |
| T1550.002 Pass the Hash |
ToolMimikatz | Mimikatz's |
| T1550.002 Pass the Hash |
ToolCrackMapExec | CrackMapExec can pass the hash to authenticate via SMB. |
| T1550.003 Pass the Ticket |
GroupAPT32 | APT32 successfully gained remote access by using pass the ticket. |
| T1550.003 Pass the Ticket |
GroupAPT29 | APT29 used Kerberos ticket attacks for lateral movement. |
| T1550.003 Pass the Ticket |
GroupBRONZE BUTLER | BRONZE BUTLER has created forged Kerberos Ticket Granting Ticket (TGT) and Ticket Granting Service (TGS) tickets to maintain administrative access. |
| T1550.003 Pass the Ticket |
MalwareSeaDuke | Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication. |
| T1550.003 Pass the Ticket |
ToolMimikatz | Mimikatz’s |
| T1550.003 Pass the Ticket |
ToolPupy | Pupy can also perform pass-the-ticket. |
| T1550.004 Web Session Cookie |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account. |
| T1550.004 Web Session Cookie |
GroupStar Blizzard | Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx. |
| T1552 Unsecured Credentials |
CampaignLeviathan Australian Intrusions | Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions. |
| T1552 Unsecured Credentials |
GroupVolt Typhoon | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances. |
| T1552 Unsecured Credentials |
MalwareDarkGate | DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe. |
| T1552 Unsecured Credentials |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1552 Unsecured Credentials |
ToolNPPSPY | NPPSPY captures credentials by recording them through an alternative network listener registered to the |
| T1552 Unsecured Credentials |
ToolPacu | Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates. |
| T1552.001 Credentials In Files |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors accessed web.config and machine.config to extract MachineKey values, enabling them to forge legitimate VIEWSTATE tokens for future deserialization payloads. |
| T1552.001 Credentials In Files |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to extract authentication certificates stored in system configuration files across compromised environments. |
| T1552.001 Credentials In Files |
CampaignLeviathan Australian Intrusions | Leviathan gathered credentials stored in files related to Building Management System (BMS) operations during Leviathan Australian Intrusions. |
| T1552.001 Credentials In Files |
GroupIndrik Spider | Indrik Spider has searched files to obtain and exfiltrate credentials. |
| T1552.001 Credentials In Files |
GroupAPT3 | APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome. |
| T1552.001 Credentials In Files |
GroupKimsuky | Kimsuky has used tools that are capable of obtaining credentials from saved mail. |
| T1552.001 Credentials In Files |
GroupMuddyWater | MuddyWater has run a tool that steals passwords saved in victim email. |
| T1552.001 Credentials In Files |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1552.001 Credentials In Files |
GroupTeamTNT | TeamTNT has searched for unsecured AWS credentials and Docker API credentials. |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1552.001 Credentials In Files |
GroupTA505 | TA505 has used malware to gather credentials from FTP clients and Outlook. |
| T1552.001 Credentials In Files |
GroupRedCurl | |
| T1552.001 Credentials In Files |
GroupEmber Bear | Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials. |
| T1552.001 Credentials In Files |
GroupFox Kitten | Fox Kitten has accessed files to gain valid credentials. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.001 Credentials In Files |
GroupFIN13 | FIN13 has obtained administrative credentials by browsing through local files on a compromised machine. |
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1552.001 Credentials In Files |
MalwareSmoke Loader | Smoke Loader searches for files named logins.json to parse for credentials. |
| T1552.001 Credentials In Files |
MalwareEmotet | Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user. |
| T1552.001 Credentials In Files |
MalwareHildegard | Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens. |
| T1552.001 Credentials In Files |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store. |
| T1552.001 Credentials In Files |
MalwareXTunnel | XTunnel is capable of accessing locally stored passwords on victims. |
| T1552.001 Credentials In Files |
Malwarepngdowner | If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.001 Credentials In Files |
MalwarePysa | Pysa has extracted credentials from the password database before encrypting the files. |
| T1552.001 Credentials In Files |
MalwareShai-Hulud | Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files. |
| T1552.001 Credentials In Files |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from configuration or support files. |
| T1552.001 Credentials In Files |
MalwarejRAT | jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk. |
| T1552.001 Credentials In Files |
MalwareAzorult | Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam. |
| T1552.001 Credentials In Files |
ToolAADInternals | AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.