ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
GroupUNC3886

UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs.

T1068
Exploitation for Privilege Escalation
GroupOilRig

OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088.

T1068
Exploitation for Privilege Escalation
GroupMoustachedBouncer

MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights.

T1068
Exploitation for Privilege Escalation
GroupTurla

Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
GroupBITTER

BITTER has exploited CVE-2021-1732 for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
GroupWhitefly

Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupTonto Team

Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupLAPSUS$

LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation.

T1068
Exploitation for Privilege Escalation
GroupCobalt Group

Cobalt Group has used exploits to increase their levels of rights and privileges.

T1068
Exploitation for Privilege Escalation
GroupPLATINUM

PLATINUM has leveraged a zero-day vulnerability to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

T1068
Exploitation for Privilege Escalation
GroupAPT33

APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1069
Permission Groups Discovery
GroupAPT3

APT3 has a tool that can enumerate the permissions associated with Windows groups.

T1069
Permission Groups Discovery
GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.

T1069
Permission Groups Discovery
GroupAPT41

APT41 used net group commands to enumerate various Windows user groups and permissions.

T1069
Permission Groups Discovery
GroupScattered Spider

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

T1069
Permission Groups Discovery
GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1069
Permission Groups Discovery
GroupFIN13

FIN13 has enumerated all users and roles from a victim's main treasury system.

T1069.001
Local Groups
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: net localgroup administrator >> %temp%\download

T1069.001
Local Groups
GroupVolt Typhoon

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.

T1069.001
Local Groups
GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

T1069.001
Local Groups
GroupTurla

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.

T1069.001
Local Groups
GroupChimera

Chimera has used net localgroup administrators to identify accounts with local administrative rights.

T1069.001
Local Groups
GroupTonto Team

Tonto Team has used the ShowLocalGroupDetails command to identify administrator, user, and guest accounts on a compromised host.

T1069.001
Local Groups
GroupHEXANE

HEXANE has run `net localgroup` to enumerate local groups.

T1069.002
Domain Groups
GroupVolt Typhoon

Volt Typhoon has run `net group` in compromised environments to discover domain groups.

T1069.002
Domain Groups
GroupDragonfly

Dragonfly has used batch scripts to enumerate administrators and users in the domain.

T1069.002
Domain Groups
GroupFIN7

FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups.

T1069.002
Domain Groups
GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

T1069.002
Domain Groups
GroupScattered Spider

Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser.

T1069.002
Domain Groups
GroupOilRig

OilRig has used net group /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to find domain group permission settings.

T1069.002
Domain Groups
GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

T1069.002
Domain Groups
GroupTurla

Turla has used net group "Domain Admins" /domain to identify domain administrators.

T1069.002
Domain Groups
GroupMedusa Group

Medusa Group has utilized the `net group` command to query domain groups within the victim environment.

T1069.002
Domain Groups
GroupToddyCat

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1069.002
Domain Groups
GroupINC Ransom

INC Ransom has enumerated domain groups on targeted hosts.

T1069.002
Domain Groups
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network.

T1069.002
Domain Groups
GroupInception

Inception has used specific malware modules to gather domain membership.

T1069.003
Cloud Groups
GroupShinyHunters

ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts.

T1070
Indicator Removal
GroupMustang Panda

Mustang Panda has deleted registry keys that store data and maintained persistence.

T1070
Indicator Removal
GroupAPT42

APT42 has cleared Chrome browser history.

T1070
Indicator Removal
GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070
Indicator Removal
GroupLazarus Group

Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked.

T1070.003
Clear Command History
GroupAPT41

APT41 attempted to remove evidence of some of its activity by deleting Bash histories.

T1070.003
Clear Command History
GroupmenuPass

menuPass has used Wevtutil to remove PowerShell execution logs.

T1070.003
Clear Command History
GroupTeamTNT

TeamTNT has cleared command history with history -c.

T1070.003
Clear Command History
GroupAquatic Panda

Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.