ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1003.005
Cached Domain Credentials
MalwareOkrum

Okrum was seen using modified Quarks PwDump to perform credential dumping.

T1003.005
Cached Domain Credentials
ToolLaZagne

LaZagne can perform credential dumping from MSCache to obtain account and password information.

T1003.005
Cached Domain Credentials
ToolCachedump

Cachedump can extract cached password hashes from cache entry information.

T1003.005
Cached Domain Credentials
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1003.006
DCSync
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync.

T1003.006
DCSync
GroupEarth Lusca

Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.

T1003.006
DCSync
CampaignC0027

During C0027, Scattered Spider performed domain replication.

T1003.006
DCSync
GroupMustang Panda

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

T1003.006
DCSync
GroupStorm-0501

Storm-0501 has utilized DCSync to extract credentials from victims.

T1003.006
DCSync
CampaignOperation Wocao

During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system.

T1003.006
DCSync
GroupLAPSUS$

LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines.

T1003.006
DCSync
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers.

T1003.007
Proc Filesystem
MalwarePACEMAKER

PACEMAKER has the ability to extract credentials from OS memory.

T1003.007
Proc Filesystem
ToolMimiPenguin

MimiPenguin can use the `<PID>/maps` and `<PID>/mem` file to search for regex patterns and dump the process memory.

T1003.007
Proc Filesystem
ToolLaZagne

LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory.

T1003.007
Proc Filesystem
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens.

T1003.007
Proc Filesystem
MalwareMini Shai-Hulud

Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens.

T1003.008
/etc/passwd and /etc/shadow
CampaignShadowRay

During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes.

T1003.008
/etc/passwd and /etc/shadow
ToolLaZagne

LaZagne can obtain credential information from /etc/shadow using the shadow.py module.

T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1005
Data from Local System
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems.

T1005
Data from Local System
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to gather various local system information.

T1005
Data from Local System
CampaignOperation Honeybee

During Operation Honeybee, the threat actors collected data from compromised hosts.

T1005
Data from Local System
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems.

T1005
Data from Local System
CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1005
Data from Local System
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data.

T1005
Data from Local System
CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

T1005
Data from Local System
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 extracted files from compromised networks.

T1005
Data from Local System
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.

T1005
Data from Local System
CampaignNight Dragon

During Night Dragon, the threat actors collected files and other data from compromised systems.

T1005
Data from Local System
CampaignOperation Wocao

During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system.

T1005
Data from Local System
CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1005
Data from Local System
CampaignC0026

During C0026, the threat actors collected documents from compromised hosts.

T1005
Data from Local System
CampaignCostaRicto

During CostaRicto, the threat actors collected data and files from compromised networks.

T1005
Data from Local System
GroupAPT38

APT38 has collected data from a compromised host.

T1005
Data from Local System
GroupGALLIUM

GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.

T1005
Data from Local System
GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1005
Data from Local System
GroupPatchwork

Patchwork collected and exfiltrated files from the infected system.

T1005
Data from Local System
GroupAPT41

APT41 has uploaded files and data from a compromised host.

T1005
Data from Local System
GroupDragonfly

Dragonfly has collected data from local victim systems.

T1005
Data from Local System
GroupmenuPass

menuPass has collected various files from the compromised computers.

T1005
Data from Local System
GroupHAFNIUM

HAFNIUM has collected data and files from a compromised machine.

T1005
Data from Local System
GroupFIN6

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1005
Data from Local System
GroupGamaredon Group

Gamaredon Group has collected files from infected systems and uploaded them to a C2 server.

T1005
Data from Local System
GroupFIN7

FIN7 has collected files and other sensitive information from a compromised network.

T1005
Data from Local System
GroupSandworm Team

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.