Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupFIN10 | FIN10 has used RDP to move laterally to systems in the victim environment. |
| T1021.001 Remote Desktop Protocol |
GroupFIN8 | FIN8 has used RDP for lateral movement. |
| T1021.001 Remote Desktop Protocol |
GroupFIN13 | FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT3 | APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT41 | APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT32 | APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| T1021.002 SMB/Windows Admin Shares |
GroupStorm-1811 | Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket. |
| T1021.002 SMB/Windows Admin Shares |
GroupSandworm Team | Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT39 | APT39 has used SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupMoses Staff | Moses Staff has used batch scripts that can enable SMB on a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
GroupOrangeworm | Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS. |
| T1021.002 SMB/Windows Admin Shares |
GroupAquatic Panda | Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupKe3chang | Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupTurla | Turla used |
| T1021.002 SMB/Windows Admin Shares |
GroupCinnamon Tempest | Cinnamon Tempest has used SMBexec for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupChimera | Chimera has used Windows admin shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
GroupMirrorFace | MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupDeep Panda | Deep Panda uses net.exe to connect to network shares using |
| T1021.002 SMB/Windows Admin Shares |
GroupToddyCat | ToddyCat has used locally mounted network shares for lateral movement through targated environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT28 | APT28 has mapped network drives using Net and administrator credentials. |
| T1021.002 SMB/Windows Admin Shares |
GroupFox Kitten | Fox Kitten has used valid accounts to access SMB shares. |
| T1021.002 SMB/Windows Admin Shares |
GroupLazarus Group | Lazarus Group malware SierraAlfa accesses the |
| T1021.002 SMB/Windows Admin Shares |
GroupThreat Group-1314 | Threat Group-1314 actors mapped network drives using |
| T1021.002 SMB/Windows Admin Shares |
GroupWizard Spider | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupVelvet Ant | Velvet Ant has transferred tools within victim environments using SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupPlay | Play has used Cobalt Strike to move laterally via SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN8 | FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN13 | FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers. |
| T1021.004 SSH |
GroupIndrik Spider | Indrik Spider has used SSH for lateral movement. |
| T1021.004 SSH |
GroupGCMAN | GCMAN uses Putty for lateral movement. |
| T1021.004 SSH |
GroupSalt Typhoon | Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs). |
| T1021.004 SSH |
GroupmenuPass | menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1021.004 SSH |
GroupStorm-1811 | Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access. |
| T1021.004 SSH |
GroupTeamTNT | TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them. |
| T1021.004 SSH |
GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| T1021.004 SSH |
GroupRocke | Rocke has spread its coinminer via SSH. |
| T1021.004 SSH |
GroupScattered Spider | Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI. |
| T1021.004 SSH |
GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| T1021.004 SSH |
GroupUNC3886 | UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1021.004 SSH |
GroupOilRig | OilRig has used Putty to access compromised systems. |
| T1021.004 SSH |
GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1021.004 SSH |
GroupBlackTech | BlackTech has used Putty for remote access. |
| T1021.004 SSH |
GroupLeviathan | Leviathan used ssh for internal reconnaissance. |
| T1021.004 SSH |
GroupAPT5 | APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| T1021.004 SSH |
GroupFox Kitten | Fox Kitten has used the PuTTY and Plink tools for lateral movement. |
| T1021.004 SSH |
GroupLazarus Group | Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1021.004 SSH |
GroupFIN13 | FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement. |
| T1021.005 VNC |
GroupGCMAN | GCMAN uses VNC for lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.