ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1555.005
Password Managers
GroupStorm-0501

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.

T1555.005
Password Managers
GroupFox Kitten

Fox Kitten has used scripts to access credential information from the KeePass database.

T1555.005
Password Managers
GroupLAPSUS$

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.

T1555.005
Password Managers
GroupThreat Group-3390

Threat Group-3390 obtained a KeePass database from a compromised host.

T1555.006
Cloud Secrets Management Stores
GroupHAFNIUM

HAFNIUM has moved laterally from on-premises environments to steal passwords from Azure key vaults.

T1555.006
Cloud Secrets Management Stores
GroupStorm-0501

Storm-0501 has utilized Azure Key Vault to store the encryption key using the operation `Microsoft.KeyVault/Vaults/write`.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1556
Modify Authentication Process
GroupFIN13

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.

T1556.001
Domain Controller Authentication
GroupChimera

Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential.

T1556.002
Password Filter DLL
GroupStrider

Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password.

T1556.002
Password Filter DLL
GroupOilRig

OilRig has registered a password filter DLL in order to drop malware.

T1556.002
Password Filter DLL
GroupMirrorFace

MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.

T1556.006
Multi-Factor Authentication
GroupScattered Spider

After compromising user accounts, Scattered Spider registers their own MFA tokens.

T1556.007
Hybrid Identity
GroupAPT29

APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name.

T1556.009
Conditional Access Policies
GroupScattered Spider

Scattered Spider has added additional trusted locations to Azure AD conditional access policies.

T1556.009
Conditional Access Policies
GroupStorm-0501

Storm-0501 has registered their own MFA method, and leveraged a victim hybrid joined server to circumvent Conditional Access Policies.

T1557
Adversary-in-the-Middle
GroupKimsuky

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.

T1557
Adversary-in-the-Middle
GroupMustang Panda

Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload.

T1557
Adversary-in-the-Middle
GroupSea Turtle

Sea Turtle modified DNS records at service providers to redirect traffic from legitimate resources to Sea Turtle-controlled servers to enable adversary-in-the-middle attacks for credential capture.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupLazarus Group

Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupWizard Spider

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.

T1557.002
ARP Cache Poisoning
GroupCleaver

Cleaver has used custom tools to facilitate ARP cache poisoning.

T1557.002
ARP Cache Poisoning
GroupLuminousMoth

LuminousMoth has used ARP spoofing to redirect a compromised machine to an actor-controlled website.

T1557.004
Evil Twin
GroupAPT28

APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware.

T1558
Steal or Forge Kerberos Tickets
GroupAkira

Akira have used scripts to dump Kerberos authentication credentials.

T1558.001
Golden Ticket
GroupKe3chang

Ke3chang has used Mimikatz to generate Kerberos golden tickets.

T1558.003
Kerberoasting
GroupIndrik Spider

Indrik Spider has conducted Kerberoasting attacks using a module from GitHub.

T1558.003
Kerberoasting
GroupFIN7

FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1559.001
Component Object Model
GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1559.001
Component Object Model
GroupGamaredon Group

Gamaredon Group malware can insert malicious macros into documents using a Microsoft.Office.Interop object.

T1559.001
Component Object Model
GroupMedusa Group

Medusa Group has leveraged Component Object Model (COM) to bypass UAC.

T1559.002
Dynamic Data Exchange
GroupPatchwork

Patchwork leveraged the DDE protocol to deliver their malware.

T1559.002
Dynamic Data Exchange
GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

T1559.002
Dynamic Data Exchange
GroupGallmaker

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

T1559.002
Dynamic Data Exchange
GroupFIN7

FIN7 spear phishing campaigns have included malicious Word documents with DDE execution.

T1559.002
Dynamic Data Exchange
GroupSidewinder

Sidewinder has used the ActiveXObject utility to create OLE objects to obtain execution through Internet Explorer.

T1559.002
Dynamic Data Exchange
GroupAPT37

APT37 has used Windows DDE for execution of commands and a malicious VBS.

T1559.002
Dynamic Data Exchange
GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

T1559.002
Dynamic Data Exchange
GroupTA505

TA505 has leveraged malicious Word documents that abused DDE.

T1559.002
Dynamic Data Exchange
GroupBITTER

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

T1559.002
Dynamic Data Exchange
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

T1559.002
Dynamic Data Exchange
GroupCobalt Group

Cobalt Group has sent malicious Word OLE compound documents to victims.

T1560
Archive Collected Data
GroupBlackByte

BlackByte compressed data collected from victim environments prior to exfiltration.

T1560
Archive Collected Data
GroupPatchwork

Patchwork encrypted the collected files' path with AES and then encoded them with base64.

T1560
Archive Collected Data
GroupDragonfly

Dragonfly has compressed data into .zip files prior to exfiltration.

T1560
Archive Collected Data
GroupmenuPass

menuPass has encrypted files and information before exfiltration.

T1560
Archive Collected Data
GroupAPT32

APT32's backdoor has used LZMA compression and RC4 encryption before exfiltration.

T1560
Archive Collected Data
GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.