ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.004
LSA Secrets
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

T1003.004
LSA Secrets
GroupEmber Bear

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.006
DCSync
GroupEarth Lusca

Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.

T1003.006
DCSync
GroupMustang Panda

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

T1003.006
DCSync
GroupStorm-0501

Storm-0501 has utilized DCSync to extract credentials from victims.

T1003.006
DCSync
GroupLAPSUS$

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.

T1005
Data from Local System
GroupAPT38

APT38 has collected data from a compromised host.

T1005
Data from Local System
GroupGALLIUM

GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.

T1005
Data from Local System
GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1005
Data from Local System
GroupPatchwork

Patchwork collected and exfiltrated files from the infected system.

T1005
Data from Local System
GroupAPT41

APT41 has uploaded files and data from a compromised host.

T1005
Data from Local System
GroupDragonfly

Dragonfly has collected data from local victim systems.

T1005
Data from Local System
GroupmenuPass

menuPass has collected various files from the compromised computers.

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1005
Data from Local System
GroupFIN6

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1005
Data from Local System
GroupGamaredon Group

Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.

T1005
Data from Local System
GroupFIN7

FIN7 has collected files and other sensitive information from a compromised network.

T1005
Data from Local System
GroupSandworm Team

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

T1005
Data from Local System
GroupAndariel

Andariel has collected large numbers of files from compromised network systems for later extraction.

T1005
Data from Local System
GroupCURIUM

CURIUM has exfiltrated data from a compromised machine.

T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1005
Data from Local System
GroupAPT37

APT37 has collected data from victims' local systems.

T1005
Data from Local System
GroupOilRig

OilRig has used PowerShell to upload files from compromised systems.

T1005
Data from Local System
GroupWindigo

Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors.

T1005
Data from Local System
GroupAquatic Panda

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1005
Data from Local System
GroupAPT1

APT1 has collected files from a local victim.

T1005
Data from Local System
GroupTurla

Turla RPC backdoors can upload files from victim machines.

T1005
Data from Local System
GroupRedCurl

RedCurl has collected data from the local disk of compromised hosts.

T1005
Data from Local System
GroupStealth Falcon

Stealth Falcon malware gathers data from the local victim system.

T1005
Data from Local System
GroupAPT29

APT29 has stolen data from compromised hosts.

T1005
Data from Local System
GroupDark Caracal

Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems.

T1005
Data from Local System
GroupMirrorFace

MirrorFace gathered data and files of interest from victim's systems.

T1005
Data from Local System
GroupBRONZE BUTLER

BRONZE BUTLER has exfiltrated files stolen from local systems.

T1005
Data from Local System
GroupAxiom

Axiom has collected data from a compromised network.

T1005
Data from Local System
GroupEmber Bear

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1005
Data from Local System
GroupToddyCat

ToddyCat has run scripts to collect documents from targeted hosts.

T1005
Data from Local System
GroupLuminousMoth

LuminousMoth has collected files and data from compromised machines.

T1005
Data from Local System
GroupAgrius

Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1005
Data from Local System
GroupFox Kitten

Fox Kitten has searched local system resources to access sensitive documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.