Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.002 Domain Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.002 Domain Account |
GroupRedCurl | RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality . |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1087.002 Domain Account |
GroupMirrorFace | MirrorFace has used native Windows tools to obtain domain user information. |
| T1087.002 Domain Account |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1087.002 Domain Account |
GroupToddyCat | ToddyCat has run `net user %USER% /dom` for account discovery. |
| T1087.002 Domain Account |
GroupFox Kitten | Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts. |
| T1087.002 Domain Account |
GroupINC Ransom | INC Ransom has scanned for domain admin accounts in compromised environments. |
| T1087.002 Domain Account |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1087.002 Domain Account |
GroupWizard Spider | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data. |
| T1087.002 Domain Account |
GroupVOID MANTICORE | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment. |
| T1087.002 Domain Account |
GroupFIN13 | FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`. |
| T1087.003 Email Account |
GroupSandworm Team | Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application. |
| T1087.003 Email Account |
GroupTA505 | TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server. |
| T1087.003 Email Account |
GroupRedCurl | RedCurl has collected information about email accounts. |
| T1087.003 Email Account |
GroupMagic Hound | Magic Hound has used Powershell to discover email accounts. |
| T1087.004 Cloud Account |
GroupStorm-0501 | Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound. |
| T1087.004 Cloud Account |
GroupAPT29 | APT29 has conducted enumeration of Azure AD accounts. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090 Proxy |
GroupAPT41 | APT41 used a tool called CLASSFON to covertly proxy network communications. |
| T1090 Proxy |
GroupMuddyWater | MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France. |
| T1090 Proxy |
GroupGamaredon Group | Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic. |
| T1090 Proxy |
GroupSandworm Team | Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally. |
| T1090 Proxy |
GroupScattered Spider | Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs. |
| T1090 Proxy |
GroupContagious Interview | Contagious Interview has leveraged Astrill VPN for C2. |
| T1090 Proxy |
GroupWindigo | Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure. |
| T1090 Proxy |
GroupPOLONIUM | POLONIUM has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMoustachedBouncer | MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks. |
| T1090 Proxy |
GroupBlue Mockingbird | Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections. |
| T1090 Proxy |
GroupTurla | Turla RPC backdoors have included local UPnP RPC proxies. |
| T1090 Proxy |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool. |
| T1090 Proxy |
GroupMirrorFace | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool. |
| T1090 Proxy |
GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| T1090 Proxy |
GroupEarth Lusca | Earth Lusca adopted Cloudflare as a proxy for compromised servers. |
| T1090 Proxy |
GroupLAPSUS$ | LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims. |
| T1090 Proxy |
GroupCopyKittens | CopyKittens has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupMagic Hound | Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic. |
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1090.001 Internal Proxy |
GroupStrider | Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access. |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1090.001 Internal Proxy |
GroupHigaisa | Higaisa discovered system proxy settings and used them if available. |
| T1090.001 Internal Proxy |
GroupTurla | Turla has compromised internal network systems to act as a proxy to forward traffic to C2. |
| T1090.001 Internal Proxy |
GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.001 Internal Proxy |
GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| T1090.001 Internal Proxy |
GroupVelvet Ant | Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes. |
| T1090.001 Internal Proxy |
GroupFIN13 | FIN13 has utilized a proxy tool to communicate between compromised assets. |
| T1090.002 External Proxy |
GroupGALLIUM | GALLIUM used a modified version of HTRAN to redirect connections between networks. |
| T1090.002 External Proxy |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1090.002 External Proxy |
GroupmenuPass | menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.