ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupFIN10

FIN10 has used RDP to move laterally to systems in the victim environment.

T1021.001
Remote Desktop Protocol
GroupFIN8

FIN8 has used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
GroupFIN13

FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupBlackByte

BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations.

T1021.002
SMB/Windows Admin Shares
GroupAPT3

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupAPT41

APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI).

T1021.002
SMB/Windows Admin Shares
GroupAPT32

APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.

T1021.002
SMB/Windows Admin Shares
GroupStorm-1811

Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket.

T1021.002
SMB/Windows Admin Shares
GroupSandworm Team

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.

T1021.002
SMB/Windows Admin Shares
GroupAPT39

APT39 has used SMB for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupMoses Staff

Moses Staff has used batch scripts that can enable SMB on a compromised host.

T1021.002
SMB/Windows Admin Shares
GroupOrangeworm

Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS.

T1021.002
SMB/Windows Admin Shares
GroupAquatic Panda

Aquatic Panda used remote shares to enable lateral movement in victim environments.

T1021.002
SMB/Windows Admin Shares
GroupKe3chang

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1021.002
SMB/Windows Admin Shares
GroupBlue Mockingbird

Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB.

T1021.002
SMB/Windows Admin Shares
GroupTurla

Turla used net use commands to connect to lateral systems within a network.

T1021.002
SMB/Windows Admin Shares
GroupCinnamon Tempest

Cinnamon Tempest has used SMBexec for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupChimera

Chimera has used Windows admin shares to move laterally.

T1021.002
SMB/Windows Admin Shares
GroupMirrorFace

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1021.002
SMB/Windows Admin Shares
GroupDeep Panda

Deep Panda uses net.exe to connect to network shares using net use commands with compromised credentials.

T1021.002
SMB/Windows Admin Shares
GroupToddyCat

ToddyCat has used locally mounted network shares for lateral movement through targated environments.

T1021.002
SMB/Windows Admin Shares
GroupAPT28

APT28 has mapped network drives using Net and administrator credentials.

T1021.002
SMB/Windows Admin Shares
GroupFox Kitten

Fox Kitten has used valid accounts to access SMB shares.

T1021.002
SMB/Windows Admin Shares
GroupLazarus Group

Lazarus Group malware SierraAlfa accesses the ADMIN$ share via SMB to conduct lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupThreat Group-1314

Threat Group-1314 actors mapped network drives using net use.

T1021.002
SMB/Windows Admin Shares
GroupWizard Spider

Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupVelvet Ant

Velvet Ant has transferred tools within victim environments using SMB.

T1021.002
SMB/Windows Admin Shares
GroupPlay

Play has used Cobalt Strike to move laterally via SMB.

T1021.002
SMB/Windows Admin Shares
GroupFIN8

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupFIN13

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.

T1021.004
SSH
GroupIndrik Spider

Indrik Spider has used SSH for lateral movement.

T1021.004
SSH
GroupGCMAN

GCMAN uses Putty for lateral movement.

T1021.004
SSH
GroupSalt Typhoon

Salt Typhoon has modified the loopback address on compromised switches and used them as the source of SSH connections to additional devices within the target environment, allowing them to bypass access control lists (ACLs).

T1021.004
SSH
GroupmenuPass

menuPass has used Putty Secure Copy Client (PSCP) to transfer data.

T1021.004
SSH
GroupStorm-1811

Storm-1811 has used OpenSSH to establish an SSH tunnel to victims for persistent access.

T1021.004
SSH
GroupTeamTNT

TeamTNT has used SSH to connect back to victim machines. TeamTNT has also used SSH to transfer tools and payloads onto victim hosts and execute them.

T1021.004
SSH
GroupFIN7

FIN7 has used SSH to move laterally through victim environments.

T1021.004
SSH
GroupRocke

Rocke has spread its coinminer via SSH.

T1021.004
SSH
GroupScattered Spider

Scattered Spider has used SSH to move laterally in victim environments and to access the vSphere vCenter Server GUI.

T1021.004
SSH
GroupAPT39

APT39 used secure shell (SSH) to move laterally among their targets.

T1021.004
SSH
GroupUNC3886

UNC3886 has established remote SSH access to targeted ESXi hosts.

T1021.004
SSH
GroupOilRig

OilRig has used Putty to access compromised systems.

T1021.004
SSH
GroupAquatic Panda

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.

T1021.004
SSH
GroupBlackTech

BlackTech has used Putty for remote access.

T1021.004
SSH
GroupLeviathan

Leviathan used ssh for internal reconnaissance.

T1021.004
SSH
GroupAPT5

APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.

T1021.004
SSH
GroupFox Kitten

Fox Kitten has used the PuTTY and Plink tools for lateral movement.

T1021.004
SSH
GroupLazarus Group

Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network.

T1021.004
SSH
GroupFIN13

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.

T1021.005
VNC
GroupGCMAN

GCMAN uses VNC for lateral movement.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.