ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
GroupLuminousMoth

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1083
File and Directory Discovery
GroupAPT28

APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms.

T1083
File and Directory Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs.

T1083
File and Directory Discovery
GroupFox Kitten

Fox Kitten has used WizTree to obtain network files and directory listings.

T1083
File and Directory Discovery
GroupWinnti Group

Winnti Group has used a program named ff.exe to search for specific documents on compromised hosts.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1083
File and Directory Discovery
GroupSowbug

Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim.

T1083
File and Directory Discovery
GroupVelvet Ant

Velvet Ant has enumerated local files and folders on victim devices.

T1083
File and Directory Discovery
GroupInception

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.

T1083
File and Directory Discovery
GroupPlay

Play has used the Grixba information stealer to list security files and processes.

T1083
File and Directory Discovery
GroupMagic Hound

Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents.

T1083
File and Directory Discovery
GroupFIN13

FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network.

T1083
File and Directory Discovery
GroupShinyHunters

ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).

T1087
Account Discovery
GroupScattered Spider

Scattered Spider has identified vSphere administrator accounts.

T1087
Account Discovery
GroupAquatic Panda

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.

T1087
Account Discovery
GroupFIN13

FIN13 has enumerated all users and their roles from a victim's main treasury system.

T1087.001
Local Account
GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

T1087.001
Local Account
Groupadmin@338

admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: net user >> %temp%\download net user /domain >> %temp%\download

T1087.001
Local Account
GroupVolt Typhoon

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.

T1087.001
Local Account
GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

T1087.001
Local Account
GroupAPT32

APT32 enumerated administrative users using the commands net localgroup administrators.

T1087.001
Local Account
GroupMoses Staff

Moses Staff has collected the administrator username from a compromised host.

T1087.001
Local Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.001
Local Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.001
Local Account
GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

T1087.001
Local Account
GroupTurla

Turla has used net user to enumerate local accounts on the system.

T1087.001
Local Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.001
Local Account
GroupRedCurl

RedCurl has collected information about local accounts.

T1087.001
Local Account
GroupLotus Blossom

Lotus Blossom has used commands such as `net` to profile local system users.

T1087.001
Local Account
GroupChimera

Chimera has used net user for account discovery.

T1087.001
Local Account
GroupMedusa Group

Medusa Group has leveraged `net user` for account discovery.

T1087.001
Local Account
GroupAPT42

APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.

T1087.001
Local Account
GroupFox Kitten

Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.

T1087.001
Local Account
GroupThreat Group-3390

Threat Group-3390 has used net user to conduct internal discovery of systems.

T1087.002
Domain Account
GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1087.002
Domain Account
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

T1087.002
Domain Account
GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

T1087.002
Domain Account
GroupmenuPass

menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data.

T1087.002
Domain Account
GroupMuddyWater

MuddyWater has used cmd.exe net user /domain to enumerate domain users.

T1087.002
Domain Account
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1087.002
Domain Account
GroupStorm-1811

Storm-1811 has performed domain account enumeration during intrusions.

T1087.002
Domain Account
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

T1087.002
Domain Account
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD.

T1087.002
Domain Account
GroupMustang Panda

Mustang Panda has utilized AdFind to identify domain users.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1087.002
Domain Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.002
Domain Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.002
Domain Account
GroupTurla

Turla has used net user /domain to enumerate domain accounts.

T1087.002
Domain Account
GroupStorm-0501

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.