Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1110.004 Credential Stuffing |
GroupChimera | Chimera has used credential stuffing against victim's remote services to obtain valid accounts. |
| T1110.004 Credential Stuffing |
GroupVOID MANTICORE | VOID MANTICORE has utilized credential stuffing attacks to obtain initial access to victim environments. |
| T1111 Multi-Factor Authentication Interception |
GroupKimsuky | Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication. |
| T1111 Multi-Factor Authentication Interception |
GroupChimera | Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS. |
| T1111 Multi-Factor Authentication Interception |
GroupAPT42 | APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
| T1111 Multi-Factor Authentication Interception |
GroupLAPSUS$ | LAPSUS$ has replayed stolen session token and passwords to trigger simple-approval MFA prompts in hope of the legitimate user will grant necessary approval. |
| T1112 Modify Registry |
GroupAPT38 | APT38 uses a tool called CLEANTOAD that has the capability to modify Registry keys. |
| T1112 Modify Registry |
GroupIndrik Spider | Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities. |
| T1112 Modify Registry |
GroupBlackByte | BlackByte performed Registry modifications to escalate privileges and disable security tools. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1112 Modify Registry |
GroupVolt Typhoon | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG). |
| T1112 Modify Registry |
GroupPatchwork | A Patchwork payload deletes Resiliency Registry keys created by Microsoft Office applications in an apparent effort to trick users into thinking there were no issues during application runs. |
| T1112 Modify Registry |
GroupAPT41 | APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials. |
| T1112 Modify Registry |
GroupDragonfly | Dragonfly has modified the Registry to perform multiple techniques through the use of Reg. |
| T1112 Modify Registry |
GroupGorgon Group | Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under |
| T1112 Modify Registry |
GroupAPT32 | APT32's backdoor has modified the Windows Registry to store the backdoor's configuration. |
| T1112 Modify Registry |
GroupGamaredon Group | Gamaredon Group has removed security settings for VBA macro execution by changing registry values |
| T1112 Modify Registry |
GroupOilRig | OilRig has used reg.exe to modify system configuration. |
| T1112 Modify Registry |
GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| T1112 Modify Registry |
GroupSaint Bear | Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
| T1112 Modify Registry |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Registry modifications to specify a DLL payload. |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1112 Modify Registry |
GroupTA505 | TA505 has used malware to disable Windows Defender through modification of the Registry. |
| T1112 Modify Registry |
GroupLotus Blossom | Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1112 Modify Registry |
GroupMedusa Group | Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access. |
| T1112 Modify Registry |
GroupEmber Bear | Ember Bear modifies registry values for anti-forensics and defense evasion purposes. |
| T1112 Modify Registry |
GroupLuminousMoth | LuminousMoth has used malware that adds Registry keys for persistence. |
| T1112 Modify Registry |
GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| T1112 Modify Registry |
GroupEarth Lusca | Earth Lusca modified the registry using the command |
| T1112 Modify Registry |
GroupSilence | Silence can create, delete, or modify a specified Registry key or value. |
| T1112 Modify Registry |
GroupWizard Spider | Wizard Spider has modified the Registry key |
| T1112 Modify Registry |
GroupMagic Hound | Magic Hound has modified Registry settings for security tools. |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1112 Modify Registry |
GroupFIN8 | FIN8 has deleted Registry keys during post compromise cleanup activities. |
| T1112 Modify Registry |
GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
| T1113 Screen Capture |
GroupKimsuky | Kimsuky has captured browser screenshots using TRANSLATEXT. Kimsuky has also obtained screen captures with custom malware. |
| T1113 Screen Capture |
GroupVolt Typhoon | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries. |
| T1113 Screen Capture |
GroupDragonfly | Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil). |
| T1113 Screen Capture |
GroupMuddyWater | MuddyWater has used malware that can capture screenshots of the victim’s machine. |
| T1113 Screen Capture |
GroupGamaredon Group | Gamaredon Group's malware can take screenshots of the compromised computer every minute. |
| T1113 Screen Capture |
GroupFIN7 | FIN7 captured screenshots and desktop video recordings. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1113 Screen Capture |
GroupOilRig | OilRig has a tool called CANDYKING to capture a screenshot of user's desktop. |
| T1113 Screen Capture |
GroupMoustachedBouncer | MoustachedBouncer has used plugins to take screenshots on targeted systems. |
| T1113 Screen Capture |
GroupGroup5 | Malware used by Group5 is capable of watching the victim's screen. |
| T1113 Screen Capture |
GroupWinter Vivern | Winter Vivern delivered PowerShell scripts capable of taking screenshots of victim machines. |
| T1113 Screen Capture |
GroupDark Caracal | Dark Caracal took screenshots using their Windows malware. |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1113 Screen Capture |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.