Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1068 Exploitation for Privilege Escalation |
GroupUNC3886 | UNC3886 has exploited zero-day vulnerability CVE-2023-20867 to enable execution of privileged commands across Windows, Linux, and PhotonOS (vCenter) guest VMs. |
| T1068 Exploitation for Privilege Escalation |
GroupOilRig | OilRig has exploited the Windows Kernel Elevation of Privilege vulnerability, CVE-2024-30088. |
| T1068 Exploitation for Privilege Escalation |
GroupMoustachedBouncer | MoustachedBouncer has exploited CVE-2021-1732 to execute malware components with elevated rights. |
| T1068 Exploitation for Privilege Escalation |
GroupTurla | Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupBITTER | BITTER has exploited CVE-2021-1732 for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT29 | APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
GroupWhitefly | Whitefly has used an open-source tool to exploit a known Windows privilege escalation vulnerability (CVE-2016-0051) on unpatched computers. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupTonto Team | Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupLAPSUS$ | LAPSUS$ has exploited unpatched vulnerabilities on internally accessible servers including JIRA, GitLab, and Confluence for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
GroupCobalt Group | Cobalt Group has used exploits to increase their levels of rights and privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupPLATINUM | PLATINUM has leveraged a zero-day vulnerability to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT33 | APT33 has used a publicly available exploit for CVE-2017-0213 to escalate privileges on a local system. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1069 Permission Groups Discovery |
GroupAPT3 | APT3 has a tool that can enumerate the permissions associated with Windows groups. |
| T1069 Permission Groups Discovery |
GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery. |
| T1069 Permission Groups Discovery |
GroupAPT41 | APT41 used |
| T1069 Permission Groups Discovery |
GroupScattered Spider | Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| T1069 Permission Groups Discovery |
GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1069 Permission Groups Discovery |
GroupFIN13 | FIN13 has enumerated all users and roles from a victim's main treasury system. |
| T1069.001 Local Groups |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: |
| T1069.001 Local Groups |
GroupVolt Typhoon | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts. |
| T1069.001 Local Groups |
GroupOilRig | OilRig has used |
| T1069.001 Local Groups |
GroupTurla | Turla has used |
| T1069.001 Local Groups |
GroupChimera | Chimera has used |
| T1069.001 Local Groups |
GroupTonto Team | Tonto Team has used the |
| T1069.001 Local Groups |
GroupHEXANE | HEXANE has run `net localgroup` to enumerate local groups. |
| T1069.002 Domain Groups |
GroupVolt Typhoon | Volt Typhoon has run `net group` in compromised environments to discover domain groups. |
| T1069.002 Domain Groups |
GroupDragonfly | Dragonfly has used batch scripts to enumerate administrators and users in the domain. |
| T1069.002 Domain Groups |
GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| T1069.002 Domain Groups |
GroupMustang Panda | Mustang Panda has leveraged AdFind to enumerate domain groups. |
| T1069.002 Domain Groups |
GroupScattered Spider | Scattered Spider has enumerated Active Directory security groups including through the use of ADExplorer, ADRecon.ps1, and Get-ADUser. |
| T1069.002 Domain Groups |
GroupOilRig | OilRig has used |
| T1069.002 Domain Groups |
GroupKe3chang | Ke3chang performs discovery of permission groups |
| T1069.002 Domain Groups |
GroupTurla | Turla has used |
| T1069.002 Domain Groups |
GroupMedusa Group | Medusa Group has utilized the `net group` command to query domain groups within the victim environment. |
| T1069.002 Domain Groups |
GroupToddyCat | ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines. |
| T1069.002 Domain Groups |
GroupINC Ransom | INC Ransom has enumerated domain groups on targeted hosts. |
| T1069.002 Domain Groups |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate groups on a victim's network. |
| T1069.002 Domain Groups |
GroupInception | Inception has used specific malware modules to gather domain membership. |
| T1069.003 Cloud Groups |
GroupShinyHunters | ShinyHunters has executed API calls to enumerate permissions for compromised AWS accounts. |
| T1070 Indicator Removal |
GroupMustang Panda | Mustang Panda has deleted registry keys that store data and maintained persistence. |
| T1070 Indicator Removal |
GroupAPT42 | APT42 has cleared Chrome browser history. |
| T1070 Indicator Removal |
GroupAPT5 | APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| T1070 Indicator Removal |
GroupLazarus Group | Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked. |
| T1070.003 Clear Command History |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by deleting Bash histories. |
| T1070.003 Clear Command History |
GroupmenuPass | menuPass has used Wevtutil to remove PowerShell execution logs. |
| T1070.003 Clear Command History |
GroupTeamTNT | TeamTNT has cleared command history with |
| T1070.003 Clear Command History |
GroupAquatic Panda | Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.