Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.001 Credentials In Files |
ToolEmpire | Empire can use various modules to search for files containing passwords. |
| T1552.001 Credentials In Files |
ToolPoshC2 | PoshC2 contains modules for searching for passwords in local and remote files. |
| T1552.001 Credentials In Files |
ToolTruffleHog | TruffleHog has obtained credentials stored in config files and credential files in victim environments. |
| T1552.001 Credentials In Files |
ToolLaZagne | LaZagne can obtain credentials from chats, databases, mail, and WiFi. |
| T1552.001 Credentials In Files |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1552.001 Credentials In Files |
ToolQuasarRAT | QuasarRAT can obtain passwords from FTP clients. |
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.001 Credentials In Files |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json. |
| T1552.001 Credentials In Files |
GroupShinyHunters | ShinyHunters has gathered PII from database infrastructure. |
| T1552.001 Credentials In Files |
MalwareKali365 | Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys. |
| T1552.002 Credentials in Registry |
GroupAPT32 | APT32 used Outlook Credential Dumper to harvest credentials stored in Windows registry. |
| T1552.002 Credentials in Registry |
GroupRedCurl | |
| T1552.002 Credentials in Registry |
GroupVOID MANTICORE | VOID MANTICORE had exported credentials from registry hives to include those stored in HKLM. |
| T1552.002 Credentials in Registry |
MalwareTrickBot | TrickBot has retrieved PuTTY credentials by querying the |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1552.002 Credentials in Registry |
MalwareValak | Valak can use the clientgrabber module to steal e-mail credentials from the Registry. |
| T1552.002 Credentials in Registry |
MalwareIceApple | IceApple can harvest credentials from local and remote host registries. |
| T1552.002 Credentials in Registry |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from the Registry. |
| T1552.002 Credentials in Registry |
ToolPowerSploit | PowerSploit has several modules that search the Windows Registry for stored credentials: |
| T1552.002 Credentials in Registry |
ToolReg | Reg may be used to find credentials in the Windows Registry. |
| T1552.003 Shell History |
MalwareKinsing | Kinsing has searched |
| T1552.003 Shell History |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners. |
| T1552.004 Private Keys |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates. |
| T1552.004 Private Keys |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store. |
| T1552.004 Private Keys |
GroupKimsuky | Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`. |
| T1552.004 Private Keys |
GroupVolt Typhoon | Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser. |
| T1552.004 Private Keys |
GroupTeamTNT | TeamTNT has searched for unsecured SSH keys. |
| T1552.004 Private Keys |
GroupRocke | Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network. |
| T1552.004 Private Keys |
GroupScattered Spider | Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host. |
| T1552.004 Private Keys |
GroupStorm-0501 | Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation. |
| T1552.004 Private Keys |
MalwareMachete | Machete has scanned and looked for cryptographic keys and certificate file extensions. |
| T1552.004 Private Keys |
MalwareMafalda | Mafalda can collect a Chrome encryption key used to protect browser cookies. |
| T1552.004 Private Keys |
MalwareHildegard | Hildegard has searched for private keys in .ssh. |
| T1552.004 Private Keys |
MalwareFoggyWeb | FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server. |
| T1552.004 Private Keys |
MalwareTroll Stealer | Troll Stealer collects all data in victim `.ssh` folders by creating a compressed copy that is subsequently exfiltrated to command and control infrastructure. Troll Stealer also collects key information associated with the Government Public Key Infrastructure (GPKI) service for South Korean government information systems. |
| T1552.004 Private Keys |
MalwareEbury | Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| T1552.004 Private Keys |
MalwareKinsing | Kinsing has searched for private keys. |
| T1552.004 Private Keys |
MalwarejRAT | jRAT can steal keys for VPNs and cryptocurrency wallets. |
| T1552.004 Private Keys |
ToolAADInternals | AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers. |
| T1552.004 Private Keys |
ToolEmpire | Empire can use modules like |
| T1552.004 Private Keys |
ToolMimikatz | Mimikatz's |
| T1552.004 Private Keys |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched victim hosts for TLS and SSH keys. |
| T1552.004 Private Keys |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh. |
| T1552.004 Private Keys |
MalwareCanisterWorm | CanisterWorm has gathered SSH private keys from the .ssh file. |
| T1552.004 Private Keys |
GroupTeamPCP | TeamPCP has used malware to extract SSH and GPG keys from victim environments. |
| T1552.005 Cloud Instance Metadata API |
GroupTeamTNT | TeamTNT has queried the AWS instance metadata service for credentials. |
| T1552.005 Cloud Instance Metadata API |
MalwareHildegard | Hildegard has queried the Cloud Instance Metadata API for cloud credentials. |
| T1552.005 Cloud Instance Metadata API |
MalwareShai-Hulud | Shai-Hulud has queried the AWS and GCP metadata endpoints for instances and service credentials. |
| T1552.005 Cloud Instance Metadata API |
ToolTruffleHog | TruffleHog can query the AWS and GCP metadata endpoints for instances and service credentials. |
| T1552.005 Cloud Instance Metadata API |
ToolPeirates | Peirates can query the query AWS and GCP metadata APIs for secrets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.