Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareHelminth | Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server. |
| T1074.001 Local Data Staging |
MalwareDtrack | Dtrack can save collected data to disk, different file formats, and network shares. |
| T1074.001 Local Data Staging |
MalwareSLOWPULSE | SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`. |
| T1074.001 Local Data Staging |
MalwareADVSTORESHELL | ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1074.001 Local Data Staging |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has created a staging file in `/tmp` for collected data. |
| T1074.001 Local Data Staging |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| T1074.002 Remote Data Staging |
Malwareccf32 | ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor. |
| T1078 Valid Accounts |
MalwareLinux Rabbit | Linux Rabbit acquires valid SSH accounts through brute force. |
| T1078 Valid Accounts |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1078 Valid Accounts |
MalwareLP-Notes | LP-Notes has used stolen Windows credentials to log in as the users. |
| T1078 Valid Accounts |
MalwareKinsing | Kinsing has used valid SSH credentials to access remote hosts. |
| T1078 Valid Accounts |
MalwareIndustroyer | Industroyer can use supplied user credentials to execute processes and stop services. |
| T1078 Valid Accounts |
MalwareDtrack | Dtrack used hard-coded credentials to gain access to a network share. |
| T1078 Valid Accounts |
MalwareDuqu | Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1078.001 Default Accounts |
MalwareStuxnet | Stuxnet infected WinCC machines via a hardcoded database server password. |
| T1078.001 Default Accounts |
MalwareHyperStack | HyperStack can use default credentials to connect to IPC$ shares on remote machines. |
| T1078.002 Domain Accounts |
MalwareStuxnet | Stuxnet attempts to access network resources with a domain account’s credentials. |
| T1078.002 Domain Accounts |
MalwareShamoon | If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion. |
| T1078.002 Domain Accounts |
MalwareRyuk | Ryuk can use stolen domain admin accounts to move laterally within a victim domain. |
| T1078.002 Domain Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a domain user account. |
| T1078.002 Domain Accounts |
MalwareCreepySnail | CreepySnail can use stolen credentials to authenticate on target networks. |
| T1078.003 Local Accounts |
MalwareEmotet | Emotet can brute force a local admin password, then use it to facilitate lateral movement. |
| T1078.003 Local Accounts |
MalwareUmbreon | Umbreon creates valid local users to provide access to the system. |
| T1078.003 Local Accounts |
MalwareNotPetya | NotPetya can use valid credentials with PsExec or |
| T1078.003 Local Accounts |
MalwareLockBit 3.0 | LockBit 3.0 can use a compromised local account for lateral movement. |
| T1078.003 Local Accounts |
MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account. |
| T1078.004 Cloud Accounts |
MalwareShai-Hulud | Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1078.004 Cloud Accounts |
ToolPacu | Pacu leverages valid cloud accounts to perform most of its operations. |
| T1078.004 Cloud Accounts |
ToolROADTools | ROADTools leverages valid cloud credentials to perform enumeration operations using the internal Azure AD Graph API. |
| T1078.004 Cloud Accounts |
ToolTruffleHog | TruffleHog has used stolen credentials to log into cloud services to access cloud hosted repositories and other cloud storage solutions to discover sensitive data to include API Keys, tokens and credentials. |
| T1078.004 Cloud Accounts |
ToolPeirates | Peirates can use stolen service account tokens to perform its operations. |
| T1078.004 Cloud Accounts |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages. |
| T1080 Taint Shared Content |
MalwareStuxnet | Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code. |
| T1080 Taint Shared Content |
MalwareUrsnif | Ursnif has copied itself to and infected files in network drives for propagation. |
| T1080 Taint Shared Content |
MalwareMiner-C | Miner-C copies itself into the public folder of Network Attached Storage (NAS) devices and infects new victims who open the file. |
| T1080 Taint Shared Content |
MalwareInvisiMole | InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network. |
| T1080 Taint Shared Content |
MalwareConti | Conti can spread itself by infecting other remote machines via network shared drives. |
| T1080 Taint Shared Content |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on networks shared drives. |
| T1080 Taint Shared Content |
MalwareH1N1 | H1N1 has functionality to copy itself to network shares. |
| T1082 System Information Discovery |
MalwareTrickBot | TrickBot gathers the OS version, machine name, CPU type, amount of RAM available, and UEFI/BIOS firmware information from the victim’s machine. |
| T1082 System Information Discovery |
MalwarePowerDuke | PowerDuke has commands to get information about the victim's name, build, version, serial number, and memory usage. |
| T1082 System Information Discovery |
MalwareBLINDINGCAN | BLINDINGCAN has collected from a victim machine the system name, processor information, and OS version. |
| T1082 System Information Discovery |
MalwareNinja | Ninja can obtain the computer name and information on the OS from targeted hosts. |
| T1082 System Information Discovery |
MalwarePikabot | Pikabot performs a variety of system checks and gathers system information, including commands such as |
| T1082 System Information Discovery |
MalwareRCSession | RCSession can gather system information from a compromised host. |
| T1082 System Information Discovery |
MalwareSpark | Spark can collect the hostname, keyboard layout, and language from the system. |
| T1082 System Information Discovery |
MalwareSynAck | SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries. |
| T1082 System Information Discovery |
MalwareBumblebee | Bumblebee can enumerate the OS version and domain on a targeted system. |
| T1082 System Information Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about the OS. |
| T1082 System Information Discovery |
MalwareGRIFFON | GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation . |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.