ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1068
Exploitation for Privilege Escalation
MalwareHildegard

Hildegard has used the BOtB tool which exploits CVE-2019-5736.

T1068
Exploitation for Privilege Escalation
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware exploits a vulnerability in the RTCore64.sys driver (CVE-2019-16098) to enable privilege escalation and defense evasion when run as a service.

T1068
Exploitation for Privilege Escalation
MalwareProLock

ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.

T1068
Exploitation for Privilege Escalation
MalwareInvisiMole

InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareSiloscape

Siloscape has leveraged a vulnerability in Windows containers to perform an Escape to Host.

T1068
Exploitation for Privilege Escalation
MalwareRemsec

Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges.

T1068
Exploitation for Privilege Escalation
MalwareEmbargo

Embargo has leveraged MS4Killer to deliver a vulnerable driver to the victim device, sometimes referred to as Bring Your Own Vulnerable Driver (BYOVD). Embargo has utilized the vulnerable driver probmon.sys version 3.0.0.4 which had a revoked certificated from “ITM System Co.,LTD.”

T1068
Exploitation for Privilege Escalation
MalwareJHUHUGIT

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1068
Exploitation for Privilege Escalation
MalwarePandora

Pandora can use CVE-2017-15303 to bypass Windows Driver Signature Enforcement (DSE) protection and load its driver.

T1068
Exploitation for Privilege Escalation
MalwareCobalt Strike

Cobalt Strike can exploit vulnerabilities such as MS14-058.

T1068
Exploitation for Privilege Escalation
MalwareWingbird

Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges.

T1068
Exploitation for Privilege Escalation
MalwareCarberp

Carberp has exploited multiple Windows vulnerabilities (CVE-2010-2743, CVE-2010-3338, CVE-2010-4398, CVE-2008-1084) and a .NET Runtime Optimization vulnerability for privilege escalation.

T1068
Exploitation for Privilege Escalation
MalwareXCSSET

XCSSET has used a zero-day exploit in the ssh launchdaemon to elevate privileges and bypass SIP.

T1068
Exploitation for Privilege Escalation
MalwareZox

Zox has the ability to leverage local and remote exploits to escalate privileges.

T1068
Exploitation for Privilege Escalation
ToolEmpire

Empire can exploit vulnerabilities such as MS16-032 and MS16-135.

T1068
Exploitation for Privilege Escalation
ToolPoshC2

PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099.

T1068
Exploitation for Privilege Escalation
MalwareZeroCleare

ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver.

T1069
Permission Groups Discovery
MalwareTrickBot

TrickBot can identify the groups the user on a compromised host belongs to.

T1069
Permission Groups Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about groups.

T1069
Permission Groups Discovery
MalwareSiloscape

Siloscape checks for Kubernetes node permissions.

T1069
Permission Groups Discovery
MalwareIcedID

IcedID has the ability to identify Workgroup membership.

T1069
Permission Groups Discovery
MalwareCarbon

Carbon uses the net group command.

T1069
Permission Groups Discovery
ToolShimRatReporter

ShimRatReporter gathered the local privileges for the infected host.

T1069.001
Local Groups
MalwarePOWRUNER

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.001
Local Groups
MalwareEmissary

Emissary has the capability to execute the command net localgroup administrators.

T1069.001
Local Groups
MalwareGomir

Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1069.001
Local Groups
MalwareKazuar

Kazuar gathers information about local groups and members.

T1069.001
Local Groups
MalwareFlagpro

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

T1069.001
Local Groups
MalwareExbyte

Exbyte checks whether the process is running with privileged local access during execution.

T1069.001
Local Groups
MalwareEpic

Epic gathers information on local group names.

T1069.001
Local Groups
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of local groups of users from a system.

T1069.001
Local Groups
MalwareSys10

Sys10 collects the group name of the logged-in user and sends it to the C2.

T1069.001
Local Groups
MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

T1069.001
Local Groups
MalwareKwampirs

Kwampirs collects a list of users belonging to the local users and administrators groups with the commands net localgroup administrators and net localgroup users.

T1069.001
Local Groups
MalwareJPIN

JPIN can obtain the permissions of the victim user.

T1069.001
Local Groups
MalwareLunarWeb

LunarWeb can discover local group memberships.

T1069.001
Local Groups
MalwareQakBot

QakBot can use net localgroup to enable discovery of local groups.

T1069.001
Local Groups
MalwareHelminth

Helminth has checked the local administrators group.

T1069.001
Local Groups
MalwareOSInfo

OSInfo has enumerated the local administrators group.

T1069.001
Local Groups
ToolNet

Commands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.

T1069.001
Local Groups
ToolBloodHound

BloodHound can collect information about local groups and members.

T1069.001
Local Groups
ToolSILENTTRINITY

SILENTTRINITY can obtain a list of local groups and members.

T1069.001
Local Groups
ToolPoshC2

PoshC2 contains modules, such as Get-LocAdm for enumerating permission groups.

T1069.002
Domain Groups
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.

T1069.002
Domain Groups
MalwarePOWRUNER

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1069.002
Domain Groups
MalwareBADHATCH

BADHATCH can use `net.exe group "domain admins" /domain` to identify Domain Administrators.

T1069.002
Domain Groups
MalwareGootloader

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1069.002
Domain Groups
MalwareWellMess

WellMess can identify domain group membership for the current user.

T1069.002
Domain Groups
MalwareBlackCat

BlackCat can determine if a user on a compromised host has domain admin privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.