ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1588.002
Tool
GroupDarkHydrus

DarkHydrus has obtained and used tools such as Mimikatz, Empire, and Cobalt Strike.

T1588.002
Tool
GroupBlackTech

BlackTech has obtained and used tools such as Putty, SNScan, and PsExec for its operations.

T1588.002
Tool
GroupBlue Mockingbird

Blue Mockingbird has obtained and used tools such as Mimikatz.

T1588.002
Tool
GroupTurla

Turla has obtained and customized publicly-available tools like Mimikatz.

T1588.002
Tool
GroupTA505

TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit.

T1588.002
Tool
GroupBITTER

BITTER has obtained tools such as PuTTY for use in their operations.

T1588.002
Tool
GroupDarkVishnya

DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec.

T1588.002
Tool
GroupFIN5

FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor.

T1588.002
Tool
GroupLotus Blossom

Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool.

T1588.002
Tool
GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

T1588.002
Tool
GroupCinnamon Tempest

Cinnamon Tempest has used open-source tools including customized versions of the Iox proxy tool, NPS tunneling tool, Meterpreter, and a keylogger that uploads data to Alibaba cloud storage.

T1588.002
Tool
GroupChimera

Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.

T1588.002
Tool
GroupMirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

T1588.002
Tool
GroupCleaver

Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz.

T1588.002
Tool
GroupSilent Librarian

Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations.

T1588.002
Tool
GroupMedusa Group

Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning. Medusa Group has utilized tools such as Advanced IP Scanner and SoftPerfect Network scanner for user, system and network discovery. Medusa Group has also acquired tools for command and control and defense evasion which include tunneling tools Ligolo and Cloudflared.

T1588.002
Tool
GroupBRONZE BUTLER

BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor.

T1588.002
Tool
GroupBackdoorDiplomacy

BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement.

T1588.002
Tool
GroupStar Blizzard

Star Blizzard has incorporated the open-source EvilGinx framework into their spearphishing activity.

T1588.002
Tool
GroupWhitefly

Whitefly has obtained and used tools such as Mimikatz.

T1588.002
Tool
GroupLuminousMoth

LuminousMoth has obtained an ARP spoofing tool from GitHub.

T1588.002
Tool
GroupAPT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

T1588.002
Tool
GroupMetador

Metador has used Microsoft's Console Debugger in some of their operations.

T1588.002
Tool
GroupAPT42

APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection.

T1588.002
Tool
GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

T1588.002
Tool
GroupLazarus Group

Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP.

T1588.002
Tool
GroupINC Ransom

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.

T1588.002
Tool
GroupEarth Lusca

Earth Lusca has acquired and used a variety of open source tools.

T1588.002
Tool
GroupSilence

Silence has obtained and modified versions of publicly-available tools like Empire and PsExec.

T1588.002
Tool
GroupThrip

Thrip has obtained and used tools such as Mimikatz and PsExec.

T1588.002
Tool
GroupLAPSUS$

LAPSUS$ has obtained tools such as RVTools and AD Explorer for their operations.

T1588.002
Tool
GroupCobalt Group

Cobalt Group has obtained and used a variety of tools including Mimikatz, PsExec, Cobalt Strike, and SDelete.

T1588.002
Tool
GroupCopyKittens

CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities.

T1588.002
Tool
GroupWizard Spider

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

T1588.002
Tool
GroupIndigoZebra

IndigoZebra has acquired open source tools such as NBTscan and Meterpreter for their operations.

T1588.002
Tool
GroupInception

Inception has obtained and used open-source tools such as LaZagne.

T1588.002
Tool
GroupVOID MANTICORE

VOID MANTICORE has obtained and utilized commercial VPN services, open-source software and publicly available offensive security tools to facilitate malicious activities.

T1588.002
Tool
GroupPlay

Play has used multiple tools for discovery and defense evasion purposes on compromised hosts.

T1588.002
Tool
GroupHEXANE

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.

T1588.002
Tool
GroupWIRTE

WIRTE has obtained and used Empire and Rclone for post-exploitation activities.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

T1588.002
Tool
GroupThreat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.

T1588.002
Tool
GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

T1588.002
Tool
GroupFIN10

FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.

T1588.002
Tool
GroupFIN8

FIN8 has used open-source tools such as Impacket for targeting efforts.

T1588.002
Tool
GroupFIN13

FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts.

T1588.002
Tool
GroupAPT19

APT19 has obtained and used publicly-available tools like Empire.

T1588.002
Tool
GroupPittyTiger

PittyTiger has obtained and used tools such as Mimikatz and gsecdump.

T1588.002
Tool
GroupShinyHunters

ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access.

T1588.003
Code Signing Certificates
GroupKimsuky

Kimsuky has stolen a valid certificate that is used to sign the malware and the dropper.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.