ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.002
Security Account Manager
ToolFgdump

Fgdump can dump Windows password hashes.

T1003.002
Security Account Manager
Toolpwdump

pwdump can be used to dump credentials from the SAM.

T1003.002
Security Account Manager
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the SAM table.

T1003.002
Security Account Manager
Toolgsecdump

gsecdump can dump Windows password hashes from the SAM.

T1003.002
Security Account Manager
ToolCrackMapExec

CrackMapExec can dump usernames and hashed passwords from the SAM.

T1003.002
Security Account Manager
ToolKoadic

Koadic can gather hashed passwords by dumping SAM/SECURITY hive.

T1003.003
NTDS
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information from NTDS.dit.

T1003.003
NTDS
Toolesentutl

esentutl can copy `ntds.dit` using the Volume Shadow Copy service.

T1003.003
NTDS
ToolCrackMapExec

CrackMapExec can dump hashed passwords associated with Active Directory using Windows' Directory Replication Services API (DRSUAPI), or Volume Shadow Copy.

T1003.003
NTDS
ToolKoadic

Koadic can gather hashed passwords by gathering domain controller hashes from NTDS.

T1003.004
LSA Secrets
MalwareCosmicDuke

CosmicDuke collects LSA secrets.

T1003.004
LSA Secrets
MalwareIceApple

IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`.

T1003.004
LSA Secrets
ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

T1003.004
LSA Secrets
ToolAADInternals

AADInternals can dump secrets from the Local Security Authority.

T1003.004
LSA Secrets
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the LSA.

T1003.004
LSA Secrets
Toolgsecdump

gsecdump can dump LSA secrets.

T1003.004
LSA Secrets
ToolLaZagne

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

T1003.004
LSA Secrets
ToolCrackMapExec

CrackMapExec can dump hashed passwords from LSA secrets for the targeted system.

T1003.004
LSA Secrets
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1003.005
Cached Domain Credentials
MalwareOkrum

Okrum was seen using modified Quarks PwDump to perform credential dumping.

T1003.005
Cached Domain Credentials
ToolLaZagne

LaZagne can perform credential dumping from MSCache to obtain account and password information.

T1003.005
Cached Domain Credentials
ToolCachedump

Cachedump can extract cached password hashes from cache entry information.

T1003.005
Cached Domain Credentials
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1003.006
DCSync
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

T1003.007
Proc Filesystem
MalwarePACEMAKER

PACEMAKER has the ability to extract credentials from OS memory.

T1003.007
Proc Filesystem
ToolMimiPenguin

MimiPenguin can use the `<PID>/maps` and `<PID>/mem` file to search for regex patterns and dump the process memory.

T1003.007
Proc Filesystem
ToolLaZagne

LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory.

T1003.007
Proc Filesystem
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens.

T1003.007
Proc Filesystem
MalwareMini Shai-Hulud

Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens.

T1003.008
/etc/passwd and /etc/shadow
ToolLaZagne

LaZagne can obtain credential information from /etc/shadow using the shadow.py module.

T1005
Data from Local System
MalwareTrickBot

TrickBot collects local files and information from the victim’s local machine.

T1005
Data from Local System
MalwareBLINDINGCAN

BLINDINGCAN has uploaded files from victim machines.

T1005
Data from Local System
MalwareRCSession

RCSession can collect data from a compromised host.

T1005
Data from Local System
MalwareQuietSieve

QuietSieve can collect files from a compromised host.

T1005
Data from Local System
MalwareBumblebee

Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies.

T1005
Data from Local System
MalwareBRICKSTORM

BRICKSTORM has commands that allow the actor download files from the compromised host to the C2 server, and to also download specific sections of a file.

T1005
Data from Local System
MalwareAmadey

Amadey can collect information from a compromised host.

T1005
Data from Local System
MalwareProxysvc

Proxysvc searches the local system and gathers data.

T1005
Data from Local System
Malwareyty

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.

T1005
Data from Local System
MalwareKOPILUWAK

KOPILUWAK can gather information from compromised hosts.

T1005
Data from Local System
MalwareSardonic

Sardonic has the ability to collect data from a compromised machine to deliver to the attacker.

T1005
Data from Local System
MalwareMisdat

Misdat has collected files and data from a compromised host.

T1005
Data from Local System
MalwareUrsnif

Ursnif has collected files from victim machines, including certificates and cookies.

T1005
Data from Local System
MalwareCASTLETAP

CASTLETAP can execute a C2 command to transfer files from victim machines.

T1005
Data from Local System
MalwareThreatNeedle

ThreatNeedle can collect data and files from a compromised host.

T1005
Data from Local System
MalwareHavoc

Havoc can download files from the victim's computer.

T1005
Data from Local System
MalwareFrameworkPOS

FrameworkPOS can collect elements related to credit card data from process memory.

T1005
Data from Local System
MalwareGravityRAT

GravityRAT steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf.

T1005
Data from Local System
MalwareInvisibleFerret

InvisibleFerret has collected data utilizing a script that contained a list of excluded files and directory names and naming patterns of interest such as environment and configuration files, documents, spreadsheets, and other files that contained the words secret, wallet, private, and password.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.