ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1087.002
Domain Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.002
Domain Account
GroupRedCurl

RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality .

T1087.002
Domain Account
GroupLotus Blossom

Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1087.002
Domain Account
GroupMirrorFace

MirrorFace has used native Windows tools to obtain domain user information.

T1087.002
Domain Account
GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

T1087.002
Domain Account
GroupToddyCat

ToddyCat has run `net user %USER% /dom` for account discovery.

T1087.002
Domain Account
GroupFox Kitten

Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.

T1087.002
Domain Account
GroupINC Ransom

INC Ransom has scanned for domain admin accounts in compromised environments.

T1087.002
Domain Account
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.

T1087.002
Domain Account
GroupWizard Spider

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.

T1087.002
Domain Account
GroupVOID MANTICORE

VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

T1087.003
Email Account
GroupSandworm Team

Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application.

T1087.003
Email Account
GroupTA505

TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.

T1087.003
Email Account
GroupRedCurl

RedCurl has collected information about email accounts.

T1087.003
Email Account
GroupMagic Hound

Magic Hound has used Powershell to discover email accounts.

T1087.004
Cloud Account
GroupStorm-0501

Storm-0501 has conducted enumeration of users, roles, and resources within victim Azure tenants using the tool Azurehound.

T1087.004
Cloud Account
GroupAPT29

APT29 has conducted enumeration of Azure AD accounts.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090
Proxy
GroupAPT41

APT41 used a tool called CLASSFON to covertly proxy network communications.

T1090
Proxy
GroupMuddyWater

MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France.

T1090
Proxy
GroupGamaredon Group

Gamaredon Group has used the Cloudflare Tunnel client to proxy C2 traffic.

T1090
Proxy
GroupSandworm Team

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.

T1090
Proxy
GroupScattered Spider

Scattered Spider has used proxy networks to hamper detection and has installed legitimate proxy tools on VMware vCenter and adversary-controlled VMs.

T1090
Proxy
GroupContagious Interview

Contagious Interview has leveraged Astrill VPN for C2.

T1090
Proxy
GroupWindigo

Windigo has delivered a generic Windows proxy Win32/Glubteta.M. Windigo has also used multiple reverse proxy chains as part of their C2 infrastructure.

T1090
Proxy
GroupPOLONIUM

POLONIUM has used the AirVPN service for operational activity.

T1090
Proxy
GroupMoustachedBouncer

MoustachedBouncer has used a reverse proxy tool similar to the GitHub repository revsocks.

T1090
Proxy
GroupBlue Mockingbird

Blue Mockingbird has used FRP, ssf, and Venom to establish SOCKS proxy connections.

T1090
Proxy
GroupTurla

Turla RPC backdoors have included local UPnP RPC proxies.

T1090
Proxy
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Iox port-forwarding and proxy tool.

T1090
Proxy
GroupMirrorFace

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1090
Proxy
GroupEarth Lusca

Earth Lusca adopted Cloudflare as a proxy for compromised servers.

T1090
Proxy
GroupLAPSUS$

LAPSUS$ has leverage NordVPN for its egress points when targeting intended victims.

T1090
Proxy
GroupCopyKittens

CopyKittens has used the AirVPN service for operational activity.

T1090
Proxy
GroupMagic Hound

Magic Hound has used Fast Reverse Proxy (FRP) for RDP traffic.

T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1090.001
Internal Proxy
GroupStrider

Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access.

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1090.001
Internal Proxy
GroupHigaisa

Higaisa discovered system proxy settings and used them if available.

T1090.001
Internal Proxy
GroupTurla

Turla has compromised internal network systems to act as a proxy to forward traffic to C2.

T1090.001
Internal Proxy
GroupLotus Blossom

Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments.

T1090.001
Internal Proxy
GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

T1090.001
Internal Proxy
GroupVelvet Ant

Velvet Ant has tunneled traffic from victims through an internal, compromised host to proxy communications to command and control nodes.

T1090.001
Internal Proxy
GroupFIN13

FIN13 has utilized a proxy tool to communicate between compromised assets.

T1090.002
External Proxy
GroupGALLIUM

GALLIUM used a modified version of HTRAN to redirect connections between networks.

T1090.002
External Proxy
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1090.002
External Proxy
GroupmenuPass

menuPass has used a global service provider's IP as a proxy for C2 traffic from a victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.