ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1106
Native API
GroupmenuPass

menuPass has used native APIs including GetModuleFileName, lstrcat, CreateFile, and ReadFile.

T1106
Native API
GroupGamaredon Group

Gamaredon Group malware has used CreateProcess to launch additional malicious components.

T1106
Native API
GroupSandworm Team

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1106
Native API
GroupAPT37

APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.

T1106
Native API
GroupHigaisa

Higaisa has called various native OS APIs.

T1106
Native API
GroupTropic Trooper

Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl.

T1106
Native API
GroupBlackTech

BlackTech has used built-in API functions.

T1106
Native API
GroupTurla

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.

T1106
Native API
GroupTA505

TA505 has deployed payloads that use Windows API calls on a compromised host.

T1106
Native API
GroupChimera

Chimera has used direct Windows system calls by leveraging Dumpert.

T1106
Native API
GroupMedusa Group

Medusa Group has leveraged Windows Native API functions to execute payloads.

T1106
Native API
GroupToddyCat

ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts.

T1106
Native API
GroupLazarus Group

Lazarus Group has used the Windows API ObtainUserAgentString to obtain the User-Agent from a compromised host to connect to a C2 server. Lazarus Group has also used various, often lesser known, functions to perform various types of Discovery and Process Injection.

T1106
Native API
GroupSilence

Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks.

T1106
Native API
GroupWIRTE

WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array.

T1110
Brute Force
GroupAPT38

APT38 has used brute force techniques to attempt account access when passwords are unknown or when password hashes are unavailable.

T1110
Brute Force
GroupAPT41

APT41 performed password brute-force attacks on the local admin account.

T1110
Brute Force
GroupDragonfly

Dragonfly has attempted to brute force credentials to gain access.

T1110
Brute Force
GroupAPT39

APT39 has used Ncrack to reveal credentials.

T1110
Brute Force
GroupOilRig

OilRig has used brute force techniques to obtain credentials.

T1110
Brute Force
GroupTurla

Turla may attempt to connect to systems within a victim's network using net use commands and a predefined list or collection of passwords.

T1110
Brute Force
GroupStorm-0501

Storm-0501 has leveraged brute force attacks to obtain credentials.

T1110
Brute Force
GroupDarkVishnya

DarkVishnya used brute-force attack to obtain login data.

T1110
Brute Force
GroupFIN5

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.

T1110
Brute Force
GroupEmber Bear

Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command.

T1110
Brute Force
GroupAgrius

Agrius engaged in various brute forcing activities via SMB in victim environments.

T1110
Brute Force
GroupAPT28

APT28 can perform brute force attacks to obtain credentials.

T1110
Brute Force
GroupFox Kitten

Fox Kitten has brute forced RDP credentials.

T1110
Brute Force
GroupVOID MANTICORE

VOID MANTICORE has conducted brute-force attempts against organizational VPN infrastructure.

T1110
Brute Force
GroupHEXANE

HEXANE has used brute force attacks to compromise valid credentials.

T1110
Brute Force
GroupShinyHunters

ShinyHunters has performed brute force attacks against edge devices, such as VPNs or firewall solutions.

T1110.001
Password Guessing
GroupAPT29

APT29 has successfully conducted password guessing attacks against a list of mailboxes.

T1110.001
Password Guessing
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.

T1110.001
Password Guessing
GroupVOID MANTICORE

VOID MANTICORE has conducted password guessing to gain initial access.

T1110.002
Password Cracking
GroupAPT3

APT3 has been known to brute force password hashes to be able to leverage plain text credentials.

T1110.002
Password Cracking
GroupSalt Typhoon

Salt Typhoon has cracked passwords for accounts with weak encryption obtained from the configuration files of compromised network devices.

T1110.002
Password Cracking
GroupDragonfly

Dragonfly has dropped and executed tools used for password cracking, including Hydra and CrackMapExec.

T1110.002
Password Cracking
GroupFIN6

FIN6 has extracted password hashes from ntds.dit to crack offline.

T1110.003
Password Spraying
GroupHAFNIUM

HAFNIUM has gained initial access through password spray attacks.

T1110.003
Password Spraying
GroupLeafminer

Leafminer used a tool called Total SMB BruteForcer to perform internal password spraying.

T1110.003
Password Spraying
GroupAPT29

APT29 has conducted brute force password spray attacks.

T1110.003
Password Spraying
GroupChimera

Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts.

T1110.003
Password Spraying
GroupSilent Librarian

Silent Librarian has used collected lists of names and e-mail accounts to use in password spraying attacks against private sector targets.

T1110.003
Password Spraying
GroupEmber Bear

Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords.

T1110.003
Password Spraying
GroupAgrius

Agrius engaged in password spraying via SMB in victim environments.

T1110.003
Password Spraying
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

T1110.003
Password Spraying
GroupLazarus Group

Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords.

T1110.003
Password Spraying
GroupHEXANE

HEXANE has used password spraying attacks to obtain valid credentials.

T1110.003
Password Spraying
GroupAPT33

APT33 has used password spraying to gain access to target systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.