Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1135 Network Share Discovery |
GroupTonto Team | Tonto Team has used tools such as NBTscan to enumerate network shares. |
| T1135 Network Share Discovery |
GroupINC Ransom | INC Ransom has used Internet Explorer to view folders on other systems. |
| T1135 Network Share Discovery |
GroupSowbug | Sowbug listed remote shared drives that were accessible from a victim. |
| T1135 Network Share Discovery |
GroupWizard Spider | Wizard Spider has used the “net view” command to locate mapped network shares. |
| T1135 Network Share Discovery |
GroupFIN13 | FIN13 has executed net view commands for enumeration of open shares on compromised machines. |
| T1136 Create Account |
GroupIndrik Spider | Indrik Spider used |
| T1136 Create Account |
GroupSalt Typhoon | Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`. |
| T1136 Create Account |
GroupScattered Spider | Scattered Spider creates new user identities within the compromised organization. |
| T1136.001 Local Account |
GroupIndrik Spider | Indrik Spider has created local system accounts and has added the accounts to privileged groups. |
| T1136.001 Local Account |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1136.001 Local Account |
GroupKimsuky | Kimsuky has created accounts with |
| T1136.001 Local Account |
GroupAPT41 | APT41 has created user accounts. |
| T1136.001 Local Account |
GroupDragonfly | Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target. |
| T1136.001 Local Account |
GroupLeafminer | Leafminer used a tool called Imecab to set up a persistent remote access account on the victim machine. |
| T1136.001 Local Account |
GroupTeamTNT | TeamTNT has created local privileged users on victim machines. |
| T1136.001 Local Account |
GroupAPT39 | APT39 has created accounts on multiple compromised hosts to perform actions within the network. |
| T1136.001 Local Account |
GroupAPT5 | APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation. |
| T1136.001 Local Account |
GroupFox Kitten | Fox Kitten has created a local user account with administrator privileges. |
| T1136.001 Local Account |
GroupWizard Spider | Wizard Spider has created local administrator accounts to maintain persistence in compromised networks. |
| T1136.001 Local Account |
GroupDaggerfly | Daggerfly created a local account on victim machines to maintain access. |
| T1136.001 Local Account |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1136.001 Local Account |
GroupFIN13 | FIN13 has created MS-SQL local accounts in a compromised network. |
| T1136.002 Domain Account |
GroupBlackByte | BlackByte created privileged domain accounts during intrusions. |
| T1136.002 Domain Account |
GroupGALLIUM | GALLIUM created high-privileged domain user accounts to maintain access to victim networks. |
| T1136.002 Domain Account |
GroupHAFNIUM | HAFNIUM has created domain accounts. |
| T1136.002 Domain Account |
GroupMedusa Group | Medusa Group has created a domain account within the victim environment. |
| T1136.002 Domain Account |
GroupWizard Spider | Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence. |
| T1136.003 Cloud Account |
GroupAPT29 | APT29 can create new users through Azure AD. |
| T1136.003 Cloud Account |
GroupLAPSUS$ | LAPSUS$ has created global admin accounts in the targeted organization's cloud instances to gain persistence. |
| T1137 Office Application Startup |
GroupAPT32 | APT32 have replaced Microsoft Outlook's VbaProject.OTM file to install a backdoor macro for persistence. |
| T1137 Office Application Startup |
GroupGamaredon Group | Gamaredon Group has inserted malicious macros into existing documents, providing persistence when they are reopened. Gamaredon Group has loaded the group's previously delivered VBA project by relaunching Microsoft Outlook with the |
| T1137.001 Office Template Macros |
GroupMuddyWater | MuddyWater has used a Word Template, Normal.dotm, for persistence. |
| T1137.002 Office Test |
GroupAPT28 | APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key |
| T1137.004 Outlook Home Page |
GroupOilRig | OilRig has abused the Outlook Home Page feature for persistence. OilRig has also used CVE-2017-11774 to roll back the initial patch designed to protect against Home Page abuse. |
| T1137.006 Add-ins |
GroupNaikon | Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT38 | APT38 has used the RC4 algorithm to decrypt configuration data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupBlackByte | BlackByte has encoded commands in base64-encoded sections concatenated together in PowerShell. BlackByte uses PowerShell commands to disable Windows Defender. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKimsuky | Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure. |
| T1140 Deobfuscate/Decode Files or Information |
GroupVolt Typhoon | Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGorgon Group | Gorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file. |
| T1140 Deobfuscate/Decode Files or Information |
GroupmenuPass | menuPass has used certutil in a macro to decode base64-encoded content contained in a dropper document attached to an email. The group has also used |
| T1140 Deobfuscate/Decode Files or Information |
GroupMuddyWater | MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript. |
| T1140 Deobfuscate/Decode Files or Information |
GroupGamaredon Group | Gamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded Base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
GroupStorm-1811 | Storm-1811 has distributed password-protected archives such as ZIP files during intrusions. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTeamTNT | TeamTNT has used a script that decodes a Base64-encoded version of WeaveWorks Scope. |
| T1140 Deobfuscate/Decode Files or Information |
GroupFIN7 | FIN7 has decoded a malicious PowerShell script using `certutil -decode hex` and has decoded an XOR-obfuscated block of data with the key `qawsed1q2w3e`, which led to the installation of Lizar. |
| T1140 Deobfuscate/Decode Files or Information |
GroupSandworm Team | Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda | Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
GroupZIRCONIUM | ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code. |
| T1140 Deobfuscate/Decode Files or Information |
GroupRocke | Rocke has extracted tar.gz files after downloading them from a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.