ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1552.001
Credentials In Files
ToolEmpire

Empire can use various modules to search for files containing passwords.

T1552.001
Credentials In Files
ToolPoshC2

PoshC2 contains modules for searching for passwords in local and remote files.

T1552.001
Credentials In Files
ToolTruffleHog

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1552.001
Credentials In Files
ToolLaZagne

LaZagne can obtain credentials from chats, databases, mail, and WiFi.

T1552.001
Credentials In Files
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

T1552.001
Credentials In Files
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.

T1552.001
Credentials In Files
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.

T1552.001
Credentials In Files
GroupShinyHunters

ShinyHunters has gathered PII from database infrastructure.

T1552.001
Credentials In Files
MalwareKali365

Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys.

T1552.002
Credentials in Registry
GroupAPT32

APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry.

T1552.002
Credentials in Registry
GroupRedCurl

RedCurl used LaZagne to obtain passwords in the Registry.

T1552.002
Credentials in Registry
GroupVOID MANTICORE

VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM.

T1552.002
Credentials in Registry
MalwareTrickBot

TrickBot has retrieved PuTTY credentials by querying the Software\SimonTatham\Putty\Sessions registry key

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1552.002
Credentials in Registry
MalwareValak

Valak can use the clientgrabber module to steal e-mail credentials from the Registry.

T1552.002
Credentials in Registry
MalwareIceApple

IceApple can harvest credentials from local and remote host registries.

T1552.002
Credentials in Registry
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from the Registry.

T1552.002
Credentials in Registry
ToolPowerSploit

PowerSploit has several modules that search the Windows Registry for stored credentials: Get-UnattendedInstallFile, Get-Webconfig, Get-ApplicationHost, Get-SiteListPassword, Get-CachedGPPPassword, and Get-RegistryAutoLogon.

T1552.002
Credentials in Registry
ToolReg

Reg may be used to find credentials in the Windows Registry.

T1552.003
Shell History
MalwareKinsing

Kinsing has searched bash_history for credentials.

T1552.003
Shell History
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners.

T1552.004
Private Keys
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates.

T1552.004
Private Keys
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store.

T1552.004
Private Keys
GroupKimsuky

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.

T1552.004
Private Keys
GroupVolt Typhoon

Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser.

T1552.004
Private Keys
GroupTeamTNT

TeamTNT has searched for unsecured SSH keys.

T1552.004
Private Keys
GroupRocke

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.

T1552.004
Private Keys
GroupScattered Spider

Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host.

T1552.004
Private Keys
GroupStorm-0501

Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation.

T1552.004
Private Keys
MalwareMachete

Machete has scanned and looked for cryptographic keys and certificate file extensions.

T1552.004
Private Keys
MalwareMafalda

Mafalda can collect a Chrome encryption key used to protect browser cookies.

T1552.004
Private Keys
MalwareHildegard

Hildegard has searched for private keys in .ssh.

T1552.004
Private Keys
MalwareFoggyWeb

FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server.

T1552.004
Private Keys
MalwareTroll Stealer

Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems.

T1552.004
Private Keys
MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1552.004
Private Keys
MalwareKinsing

Kinsing has searched for private keys.

T1552.004
Private Keys
MalwarejRAT

jRAT can steal keys for VPNs and cryptocurrency wallets.

T1552.004
Private Keys
ToolAADInternals

AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers.

T1552.004
Private Keys
ToolEmpire

Empire can use modules like Invoke-SessionGopher to extract private key and session information.

T1552.004
Private Keys
ToolMimikatz

Mimikatz's CRYPTO::Extract module can extract keys by interacting with Windows cryptographic application programming interface (API) functions.

T1552.004
Private Keys
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys.

T1552.004
Private Keys
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh.

T1552.004
Private Keys
MalwareCanisterWorm

CanisterWorm has gathered SSH private keys from the .ssh file.

T1552.004
Private Keys
GroupTeamPCP

TeamPCP has used malware to extract SSH and GPG keys from victim environments.

T1552.005
Cloud Instance Metadata API
GroupTeamTNT

TeamTNT has queried the AWS instance metadata service for credentials.

T1552.005
Cloud Instance Metadata API
MalwareHildegard

Hildegard has queried the Cloud Instance Metadata API for cloud credentials.

T1552.005
Cloud Instance Metadata API
MalwareShai-Hulud

Shai-Hulud has queried the AWS and GCP metadata endpoints for instances and service credentials.

T1552.005
Cloud Instance Metadata API
ToolTruffleHog

TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials.

T1552.005
Cloud Instance Metadata API
ToolPeirates

Peirates can query the query AWS and GCP metadata APIs for secrets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.