Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1557 Adversary-in-the-Middle |
GroupKimsuky | Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website. |
| T1557 Adversary-in-the-Middle |
GroupMustang Panda | Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload. |
| T1557 Adversary-in-the-Middle |
GroupSea Turtle | Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture. |
| T1557 Adversary-in-the-Middle |
MalwareLine Runner | Line Runner intercepts HTTP requests to the victim Cisco ASA, looking for a request with a 32-character, victim dependent parameter. If that parameter matches a value in the malware, a contained payload is then written to a Lua script and executed. |
| T1557 Adversary-in-the-Middle |
MalwareDok | Dok proxies web traffic to potentially monitor and alter victim HTTP(S) traffic. |
| T1557 Adversary-in-the-Middle |
ToolNPPSPY | NPPSPY opens a new network listener for the |
| T1557 Adversary-in-the-Middle |
Toolevilginx2 | evilginx2 has the ability to act as an adversary-in-the-middle (AiTM) relay between a legitimate website and a phished user to capture all transmitted data including usernames, passwords, authentication tokens, and session cookies and tokens. |
| T1557 Adversary-in-the-Middle |
MalwareKali365 | Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupLazarus Group | Lazarus Group executed Responder using the command |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupWizard Spider | Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolImpacket | Impacket modules like ntlmrelayx and smbrelayx can be used in conjunction with Network Sniffing and Name Resolution Poisoning and SMB Relay to gather NetNTLM credentials for Brute Force or relay attacks that can gain code execution. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolEmpire | Empire can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPoshC2 | PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolResponder | Responder is used to poison name services to gather hashes and credentials from systems within a local network. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPupy | Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services. |
| T1557.002 ARP Cache Poisoning |
GroupCleaver | Cleaver has used custom tools to facilitate ARP cache poisoning. |
| T1557.002 ARP Cache Poisoning |
GroupLuminousMoth | LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website. |
| T1557.004 Evil Twin |
GroupAPT28 | APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware. |
| T1558 Steal or Forge Kerberos Tickets |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket. |
| T1558 Steal or Forge Kerberos Tickets |
GroupAkira | Akira have used scripts to dump Kerberos authentication credentials. |
| T1558.001 Golden Ticket |
GroupKe3chang | Ke3chang has used Mimikatz to generate Kerberos golden tickets. |
| T1558.001 Golden Ticket |
ToolSliver | Sliver incorporates the Rubeus framework to allow for Kerberos ticket manipulation, specifically for forging Kerberos Golden Tickets. |
| T1558.001 Golden Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use golden tickets. |
| T1558.001 Golden Ticket |
ToolMimikatz | Mimikatz's kerberos module can create golden tickets. |
| T1558.001 Golden Ticket |
ToolRubeus | Rubeus can forge a ticket-granting ticket. |
| T1558.002 Silver Ticket |
ToolAADInternals | AADInternals can be used to forge Kerberos tickets using the password hash of the AZUREADSSOACC account. |
| T1558.002 Silver Ticket |
ToolEmpire | Empire can leverage its implementation of Mimikatz to obtain and use silver tickets. |
| T1558.002 Silver Ticket |
ToolMimikatz | Mimikatz's kerberos module can create silver tickets. |
| T1558.002 Silver Ticket |
ToolRubeus | Rubeus can create silver tickets. |
| T1558.003 Kerberoasting |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline. |
| T1558.003 Kerberoasting |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerSploit's `Invoke-Kerberoast` module to request encrypted service tickets and bruteforce the passwords of Windows service accounts offline. |
| T1558.003 Kerberoasting |
CampaignLeviathan Australian Intrusions | Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions. |
| T1558.003 Kerberoasting |
GroupIndrik Spider | Indrik Spider has conducted Kerberoasting attacks using a module from GitHub. |
| T1558.003 Kerberoasting |
GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1558.003 Kerberoasting |
ToolSILENTTRINITY | SILENTTRINITY contains a module to conduct Kerberoasting. |
| T1558.003 Kerberoasting |
ToolPowerSploit | PowerSploit's |
| T1558.003 Kerberoasting |
ToolImpacket | Impacket modules like GetUserSPNs can be used to get Service Principal Names (SPNs) for user accounts. The output is formatted to be compatible with cracking tools like John the Ripper and Hashcat. |
| T1558.003 Kerberoasting |
ToolEmpire | Empire uses PowerSploit's |
| T1558.003 Kerberoasting |
ToolBrute Ratel C4 | Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking. |
| T1558.003 Kerberoasting |
ToolRubeus | Rubeus can use the `KerberosRequestorSecurityToken.GetRequest` method to request kerberoastable service tickets. |
| T1558.004 AS-REP Roasting |
ToolRubeus | Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting. |
| T1558.005 Ccache Files |
ToolImpacket | Impacket tools – such as |
| T1559 Inter-Process Communication |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors wrote output to stdout then piped it to bash for execution. |
| T1559 Inter-Process Communication |
Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus's VEILEDSIGNAL creates and listens on a Windows named pipe to exchange messages between modules. |
| T1559 Inter-Process Communication |
MalwareNinja | Ninja can use pipes to redirect the standard input and the standard output. |
| T1559 Inter-Process Communication |
MalwareRotaJakiro | When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID. |
| T1559 Inter-Process Communication |
MalwareHavoc | The Havoc SMB demon can use named pipes for communication through a parent demon. |
| T1559 Inter-Process Communication |
MalwareTONESHELL | TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr. |
| T1559 Inter-Process Communication |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.