Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackByte Ransomware | BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRyuk | Ryuk has used the C$ network share for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to move laterally via SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareKwampirs | Kwampirs copies itself over network shares to move laterally on a victim network. |
| T1021.002 SMB/Windows Admin Shares |
MalwareQilin | Qilin can embed a copy of PsExec within its payload and place it in the %Temp% directory under a randomly generated filename. |
| T1021.002 SMB/Windows Admin Shares |
MalwareZox | Zox has the ability to use SMB for communication. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNet Crawler | Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems. |
| T1021.002 SMB/Windows Admin Shares |
ToolNet | Lateral movement can be done with Net through |
| T1021.002 SMB/Windows Admin Shares |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
ToolPsExec | PsExec, a tool that has been used by adversaries, writes programs to the |
| T1021.002 SMB/Windows Admin Shares |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1021.003 Distributed Component Object Model |
MalwareCobalt Strike | Cobalt Strike can deliver Beacon payloads for lateral movement by leveraging remote COM execution. |
| T1021.003 Distributed Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM. |
| T1021.003 Distributed Component Object Model |
ToolEmpire | Empire can utilize |
| T1021.004 SSH |
CampaignCutting Edge | During Cutting Edge, threat actors used SSH for lateral movement. |
| T1021.004 SSH |
CampaignC0032 | During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution. |
| T1021.004 SSH |
CampaignLeviathan Australian Intrusions | Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions. |
| T1021.004 SSH |
GroupIndrik Spider | Indrik Spider has used SSH for lateral movement. |
| T1021.004 SSH |
GroupGCMAN | GCMAN uses Putty for lateral movement. |
| T1021.004 SSH |
GroupSalt Typhoon | Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs). |
| T1021.004 SSH |
GroupmenuPass | menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1021.004 SSH |
GroupStorm-1811 | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1021.004 SSH |
GroupTeamTNT | TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1021.004 SSH |
GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| T1021.004 SSH |
GroupRocke | Rocke has spread its coinminer via SSH. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1021.004 SSH |
GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1021.004 SSH |
GroupOilRig | OilRig has used Putty to access compromised systems. |
| T1021.004 SSH |
GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1021.004 SSH |
GroupBlackTech | BlackTech has used Putty for remote access. |
| T1021.004 SSH |
GroupLeviathan | Leviathan used ssh for internal reconnaissance. |
| T1021.004 SSH |
GroupAPT5 | APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| T1021.004 SSH |
GroupFox Kitten | Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| T1021.004 SSH |
GroupLazarus Group | Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1021.004 SSH |
GroupFIN13 | FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement. |
| T1021.004 SSH |
MalwarereGeorg | reGeorg can communicate using SSH through an HTTP tunnel. |
| T1021.004 SSH |
MalwareCobalt Strike | Cobalt Strike can SSH to a remote service. |
| T1021.004 SSH |
MalwareKinsing | Kinsing has used SSH for lateral movement. |
| T1021.004 SSH |
MalwareQilin | Qilin can enable SSH access on ESXi hosts. |
| T1021.004 SSH |
ToolEmpire | Empire contains modules for executing commands over SSH as well as in-memory VNC agent injection. |
| T1021.005 VNC |
GroupGCMAN | GCMAN uses VNC for lateral movement. |
| T1021.005 VNC |
GroupGamaredon Group | Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1021.005 VNC |
GroupFIN7 | FIN7 has used TightVNC to control compromised hosts. |
| T1021.005 VNC |
GroupFox Kitten | Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement. |
| T1021.005 VNC |
MalwareTrickBot | TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network |
| T1021.005 VNC |
MalwareLatrodectus | Latrodectus has routed C2 traffic using Keyhole VNC. |
| T1021.005 VNC |
MalwareDanBot | DanBot can use VNC for remote access to targeted systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.