Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1068 Exploitation for Privilege Escalation |
MalwareHildegard | Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1068 Exploitation for Privilege Escalation |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service. |
| T1068 Exploitation for Privilege Escalation |
MalwareProLock | ProLock can use CVE-2019-0859 to escalate privileges on a compromised host. |
| T1068 Exploitation for Privilege Escalation |
MalwareInvisiMole | InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareSiloscape | Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host. |
| T1068 Exploitation for Privilege Escalation |
MalwareRemsec | Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareEmbargo | Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.” |
| T1068 Exploitation for Privilege Escalation |
MalwareJHUHUGIT | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwarePandora | Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver. |
| T1068 Exploitation for Privilege Escalation |
MalwareCobalt Strike | Cobalt Strike can exploit vulnerabilities such as MS14-058. |
| T1068 Exploitation for Privilege Escalation |
MalwareWingbird | Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges. |
| T1068 Exploitation for Privilege Escalation |
MalwareCarberp | Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation. |
| T1068 Exploitation for Privilege Escalation |
MalwareXCSSET | XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP. |
| T1068 Exploitation for Privilege Escalation |
MalwareZox | Zox has the ability to leverage local and remote exploits to escalate privileges. |
| T1068 Exploitation for Privilege Escalation |
ToolEmpire | Empire can exploit vulnerabilities such as MS16-032 and MS16-135. |
| T1068 Exploitation for Privilege Escalation |
ToolPoshC2 | PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099. |
| T1068 Exploitation for Privilege Escalation |
MalwareZeroCleare | ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver. |
| T1069 Permission Groups Discovery |
MalwareTrickBot | TrickBot can identify the groups the user on a compromised host belongs to. |
| T1069 Permission Groups Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about groups. |
| T1069 Permission Groups Discovery |
MalwareSiloscape | Siloscape checks for Kubernetes node permissions. |
| T1069 Permission Groups Discovery |
MalwareIcedID | IcedID has the ability to identify Workgroup membership. |
| T1069 Permission Groups Discovery |
MalwareCarbon | Carbon uses the |
| T1069 Permission Groups Discovery |
ToolShimRatReporter | ShimRatReporter gathered the local privileges for the infected host. |
| T1069.001 Local Groups |
MalwarePOWRUNER | POWRUNER may collect local group information by running |
| T1069.001 Local Groups |
MalwareEmissary | Emissary has the capability to execute the command |
| T1069.001 Local Groups |
MalwareGomir | Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments. |
| T1069.001 Local Groups |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| T1069.001 Local Groups |
MalwareKazuar | Kazuar gathers information about local groups and members. |
| T1069.001 Local Groups |
MalwareFlagpro | Flagpro has been used to execute the |
| T1069.001 Local Groups |
MalwareExbyte | Exbyte checks whether the process is running with privileged local access during execution. |
| T1069.001 Local Groups |
MalwareEpic | Epic gathers information on local group names. |
| T1069.001 Local Groups |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of local groups of users from a system. |
| T1069.001 Local Groups |
MalwareSys10 | Sys10 collects the group name of the logged-in user and sends it to the C2. |
| T1069.001 Local Groups |
MalwareCobalt Strike | Cobalt Strike can use |
| T1069.001 Local Groups |
MalwareKwampirs | Kwampirs collects a list of users belonging to the local users and administrators groups with the commands |
| T1069.001 Local Groups |
MalwareJPIN | JPIN can obtain the permissions of the victim user. |
| T1069.001 Local Groups |
MalwareLunarWeb | LunarWeb can discover local group memberships. |
| T1069.001 Local Groups |
MalwareQakBot | QakBot can use |
| T1069.001 Local Groups |
MalwareHelminth | Helminth has checked the local administrators group. |
| T1069.001 Local Groups |
MalwareOSInfo | OSInfo has enumerated the local administrators group. |
| T1069.001 Local Groups |
ToolNet | Commands such as |
| T1069.001 Local Groups |
ToolBloodHound | BloodHound can collect information about local groups and members. |
| T1069.001 Local Groups |
ToolSILENTTRINITY | SILENTTRINITY can obtain a list of local groups and members. |
| T1069.001 Local Groups |
ToolPoshC2 | PoshC2 contains modules, such as |
| T1069.002 Domain Groups |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information. |
| T1069.002 Domain Groups |
MalwarePOWRUNER | POWRUNER may collect domain group information by running |
| T1069.002 Domain Groups |
MalwareBADHATCH | BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators. |
| T1069.002 Domain Groups |
MalwareGootloader | Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable. |
| T1069.002 Domain Groups |
MalwareWellMess | WellMess can identify domain group membership for the current user. |
| T1069.002 Domain Groups |
MalwareBlackCat | BlackCat can determine if a user on a compromised host has domain admin privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.