Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1588.002 Tool |
GroupBITTER | BITTER has obtained tools such as PuTTY for use in their operations. |
| T1588.002 Tool |
GroupDarkVishnya | DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec. |
| T1588.002 Tool |
GroupFIN5 | FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor. |
| T1588.002 Tool |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
| T1588.002 Tool |
GroupCinnamon Tempest | Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage. |
| T1588.002 Tool |
GroupChimera | Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1588.002 Tool |
GroupCleaver | Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz. |
| T1588.002 Tool |
GroupSilent Librarian | Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations. |
| T1588.002 Tool |
GroupMedusa Group | Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared. |
| T1588.002 Tool |
GroupBRONZE BUTLER | BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor. |
| T1588.002 Tool |
GroupBackdoorDiplomacy | BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement. |
| T1588.002 Tool |
GroupStar Blizzard | Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity. |
| T1588.002 Tool |
GroupWhitefly | |
| T1588.002 Tool |
GroupLuminousMoth | LuminousMoth has obtained an ARP spoofing tool from GitHub. |
| T1588.002 Tool |
GroupAPT28 | APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder. |
| T1588.002 Tool |
GroupMetador | Metador has used Microsoft's Console Debugger in some of their operations. |
| T1588.002 Tool |
GroupAPT42 | APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection. |
| T1588.002 Tool |
GroupAPT-C-36 | APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor. |
| T1588.002 Tool |
GroupLazarus Group | Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1588.002 Tool |
GroupEarth Lusca | Earth Lusca has acquired and used a variety of open source tools. |
| T1588.002 Tool |
GroupSilence | Silence has obtained and modified versions of publicly-available tools like Empire and PsExec. |
| T1588.002 Tool |
GroupThrip | Thrip has obtained and used tools such as Mimikatz and PsExec. |
| T1588.002 Tool |
GroupLAPSUS$ | LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations. |
| T1588.002 Tool |
GroupCobalt Group | Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete. |
| T1588.002 Tool |
GroupCopyKittens | CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities. |
| T1588.002 Tool |
GroupWizard Spider | Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts. |
| T1588.002 Tool |
GroupIndigoZebra | IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations. |
| T1588.002 Tool |
GroupInception | Inception has obtained and used open-source tools such as LaZagne. |
| T1588.002 Tool |
GroupVOID MANTICORE | VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities. |
| T1588.002 Tool |
GroupPlay | Play has used multiple tools for discovery and defense evasion purposes on compromised hosts. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
| T1588.002 Tool |
GroupWIRTE | WIRTE has obtained and used Empire and Rclone for post-exploitation activities. |
| T1588.002 Tool |
GroupMagic Hound | Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink. |
| T1588.002 Tool |
GroupThreat Group-3390 | Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor. |
| T1588.002 Tool |
GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
| T1588.002 Tool |
GroupFIN10 | FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments. |
| T1588.002 Tool |
GroupFIN8 | FIN8 has used open-source tools such as Impacket for targeting efforts. |
| T1588.002 Tool |
GroupFIN13 | FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts. |
| T1588.002 Tool |
GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
| T1588.002 Tool |
GroupPittyTiger | PittyTiger has obtained and used tools such as Mimikatz and gsecdump. |
| T1588.002 Tool |
MalwareLizar | FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
| T1588.003 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools. |
| T1588.003 Code Signing Certificates |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools with legitimate code signing certificates. |
| T1588.003 Code Signing Certificates |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates to sign DUSTTRAP malware and components. |
| T1588.003 Code Signing Certificates |
GroupKimsuky | Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper. |
| T1588.003 Code Signing Certificates |
GroupMustang Panda | Mustang Panda has used revoked code signing certificates for its malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.