Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
MalwareOkrum | Okrum was seen using modified Quarks PwDump to perform credential dumping. |
| T1003.005 Cached Domain Credentials |
ToolLaZagne | LaZagne can perform credential dumping from MSCache to obtain account and password information. |
| T1003.005 Cached Domain Credentials |
ToolCachedump | Cachedump can extract cached password hashes from cache entry information. |
| T1003.005 Cached Domain Credentials |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1003.006 DCSync |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DCSync/NetSync. |
| T1003.006 DCSync |
GroupEarth Lusca | Earth Lusca has used a |
| T1003.006 DCSync |
CampaignC0027 | During C0027, Scattered Spider performed domain replication. |
| T1003.006 DCSync |
GroupMustang Panda | Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| T1003.006 DCSync |
GroupStorm-0501 | Storm-0501 has utilized DCSync to extract credentials from victims. |
| T1003.006 DCSync |
CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz's DCSync to dump credentials from the memory of the targeted system. |
| T1003.006 DCSync |
GroupLAPSUS$ | LAPSUS$ has used DCSync attacks to gather credentials for privilege escalation routines. |
| T1003.006 DCSync |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1003.007 Proc Filesystem |
MalwarePACEMAKER | PACEMAKER has the ability to extract credentials from OS memory. |
| T1003.007 Proc Filesystem |
ToolMimiPenguin | MimiPenguin can use the `<PID>/maps` and `<PID>/mem` file to search for regex patterns and dump the process memory. |
| T1003.007 Proc Filesystem |
ToolLaZagne | LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory. |
| T1003.007 Proc Filesystem |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1003.007 Proc Filesystem |
MalwareMini Shai-Hulud | Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens. |
| T1003.008 /etc/passwd and /etc/shadow |
CampaignShadowRay | During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes. |
| T1003.008 /etc/passwd and /etc/shadow |
ToolLaZagne | LaZagne can obtain credential information from /etc/shadow using the shadow.py module. |
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1005 Data from Local System |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors extracted information from the compromised systems. |
| T1005 Data from Local System |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to gather various local system information. |
| T1005 Data from Local System |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors collected data from compromised hosts. |
| T1005 Data from Local System |
CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors stole saved cookies and login data from targeted systems. |
| T1005 Data from Local System |
CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| T1005 Data from Local System |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary tasked Claude Code to automatically gather sensitive data stored within the local system to include credentials, system configurations and sensitive operational data. |
| T1005 Data from Local System |
CampaignC0015 | During C0015, the threat actors obtained files and data from the compromised network. |
| T1005 Data from Local System |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 extracted files from compromised networks. |
| T1005 Data from Local System |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks. |
| T1005 Data from Local System |
CampaignNight Dragon | During Night Dragon, the threat actors collected files and other data from compromised systems. |
| T1005 Data from Local System |
CampaignOperation Wocao | During Operation Wocao, threat actors exfiltrated files and directories of interest from the targeted system. |
| T1005 Data from Local System |
CampaignC0017 | During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks. |
| T1005 Data from Local System |
CampaignC0026 | During C0026, the threat actors collected documents from compromised hosts. |
| T1005 Data from Local System |
CampaignCostaRicto | During CostaRicto, the threat actors collected data and files from compromised networks. |
| T1005 Data from Local System |
GroupAPT38 | APT38 has collected data from a compromised host. |
| T1005 Data from Local System |
GroupGALLIUM | GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry. |
| T1005 Data from Local System |
GroupAPT3 | APT3 will identify Microsoft Office documents on the victim's computer. |
| T1005 Data from Local System |
GroupKimsuky | Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1005 Data from Local System |
GroupVolt Typhoon | Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1005 Data from Local System |
GroupPatchwork | Patchwork collected and exfiltrated files from the infected system. |
| T1005 Data from Local System |
GroupAPT41 | APT41 has uploaded files and data from a compromised host. |
| T1005 Data from Local System |
GroupDragonfly | Dragonfly has collected data from local victim systems. |
| T1005 Data from Local System |
GroupmenuPass | menuPass has collected various files from the compromised computers. |
| T1005 Data from Local System |
GroupHAFNIUM | HAFNIUM has collected data and files from a compromised machine. |
| T1005 Data from Local System |
GroupFIN6 | FIN6 has collected and exfiltrated payment card data from compromised systems. |
| T1005 Data from Local System |
GroupGamaredon Group | Gamaredon Group has collected files from infected systems and uploaded them to a C2 server. |
| T1005 Data from Local System |
GroupFIN7 | FIN7 has collected files and other sensitive information from a compromised network. |
| T1005 Data from Local System |
GroupSandworm Team | Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.