Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.004 LSA Secrets |
GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1003.004 LSA Secrets |
GroupEmber Bear | Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.006 DCSync |
GroupEarth Lusca | Earth Lusca has used a |
| T1003.006 DCSync |
GroupMustang Panda | Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| T1003.006 DCSync |
GroupStorm-0501 | Storm-0501 has utilized DCSync to extract credentials from victims. |
| T1003.006 DCSync |
GroupLAPSUS$ | LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines. |
| T1005 Data from Local System |
GroupAPT38 | APT38 has collected data from a compromised host. |
| T1005 Data from Local System |
GroupGALLIUM | GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry. |
| T1005 Data from Local System |
GroupAPT3 | APT3 will identify Microsoft Office documents on the victim's computer. |
| T1005 Data from Local System |
GroupKimsuky | Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1005 Data from Local System |
GroupPatchwork | Patchwork collected and exfiltrated files from the infected system. |
| T1005 Data from Local System |
GroupAPT41 | APT41 has uploaded files and data from a compromised host. |
| T1005 Data from Local System |
GroupDragonfly | Dragonfly has collected data from local victim systems. |
| T1005 Data from Local System |
GroupmenuPass | menuPass has collected various files from the compromised computers. |
| T1005 Data from Local System |
GroupHAFNIUM | HAFNIUM has collected data and files from a compromised machine. |
| T1005 Data from Local System |
GroupFIN6 | FIN6 has collected and exfiltrated payment card data from compromised systems. |
| T1005 Data from Local System |
GroupGamaredon Group | Gamaredon Group has collected files from infected systems and uploaded them to a C2 server. |
| T1005 Data from Local System |
GroupFIN7 | FIN7 has collected files and other sensitive information from a compromised network. |
| T1005 Data from Local System |
GroupSandworm Team | Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts. |
| T1005 Data from Local System |
GroupAndariel | Andariel has collected large numbers of files from compromised network systems for later extraction. |
| T1005 Data from Local System |
GroupCURIUM | CURIUM has exfiltrated data from a compromised machine. |
| T1005 Data from Local System |
GroupAPT39 | APT39 has used various tools to steal files from the compromised host. |
| T1005 Data from Local System |
GroupAPT37 | APT37 has collected data from victims' local systems. |
| T1005 Data from Local System |
GroupOilRig | OilRig has used PowerShell to upload files from compromised systems. |
| T1005 Data from Local System |
GroupWindigo | Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors. |
| T1005 Data from Local System |
GroupAquatic Panda | Aquatic Panda captured local Windows security event log data from victim machines using the |
| T1005 Data from Local System |
GroupKe3chang | Ke3chang gathered information and files from local directories for exfiltration. |
| T1005 Data from Local System |
GroupAPT1 | APT1 has collected files from a local victim. |
| T1005 Data from Local System |
GroupTurla | Turla RPC backdoors can upload files from victim machines. |
| T1005 Data from Local System |
GroupRedCurl | RedCurl has collected data from the local disk of compromised hosts. |
| T1005 Data from Local System |
GroupStealth Falcon | Stealth Falcon malware gathers data from the local victim system. |
| T1005 Data from Local System |
GroupAPT29 | APT29 has stolen data from compromised hosts. |
| T1005 Data from Local System |
GroupDark Caracal | Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems. |
| T1005 Data from Local System |
GroupMirrorFace | MirrorFace gathered data and files of interest from victim's systems. |
| T1005 Data from Local System |
GroupBRONZE BUTLER | BRONZE BUTLER has exfiltrated files stolen from local systems. |
| T1005 Data from Local System |
GroupAxiom | Axiom has collected data from a compromised network. |
| T1005 Data from Local System |
GroupEmber Bear | Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1005 Data from Local System |
GroupToddyCat | ToddyCat has run scripts to collect documents from targeted hosts. |
| T1005 Data from Local System |
GroupLuminousMoth | LuminousMoth has collected files and data from compromised machines. |
| T1005 Data from Local System |
GroupAgrius | Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| T1005 Data from Local System |
GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1005 Data from Local System |
GroupFox Kitten | Fox Kitten has searched local system resources to access sensitive documents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.